NetSupportManager RAT

Aliases: NetSupport

Malware type
rat
Family
Malware family
Last IoC activity
2026-07-22 04:29:15
Profile updated
2026-07-07 13:12:17

Context

Enigma Software notes that NetSupport Manager is a genuine application, which was first released about twenty years ago. The purpose of the NetSupport Manager tool is to enable users to receive remote technical support or provide remote computer assistance. However, cyber crooks have hijacked this useful application and misappropriated it to use it in their harmful campaigns. The name of the modified version of the NetSupport Manager has been labeled the NetSupport Manager RAT.

Detection coverage

  • 2 YARA rules

Used by threat actors

  • April 2024 FIN7 Malvertising Campaign (campaign)

Detection rules

  • SEKOIA_Loader_Win_Red0044_Powershell_May24 (yara-rule)
  • CAPE_Netsupport (yara-rule)

Reports & references

  • rewterz.com — Rewterz Threat Alert Widely Abused Msix App Installer Disabled By Microsoft Active Iocs (report)
  • proofpoint.com — Clipboard Compromise Powershell Self Pwn (report)
  • rapid7.com — Ongoing Social Engineering Campaign Linked To Black Basta Ransomware Operators (report)
  • blog.sekoia.io — Exposing Fakebat Loader Distribution Methods And Adversary Infrastructure (report)
  • decoded.avast.io — Parrot Tds Takes Over Web Servers And Threatens Millions (report)
  • medium.com — Socgholish Campaigns And Initial Access Kit 4C4283Fea8Ee (report)
  • blog.sucuri.net — Css Js Steganography In Fake Flash Player Update Malware (report)
  • isc.sans.edu — 32474 (report)
  • medium.com — Smartapesg 4605157A5B80 (report)
  • team-cymru.com — Tracing The Path From Smartapesg To Netsupport Rat (report)
  • threatdown.com — Smartapesg 06 11 2024 (report)
  • malwarebytes.com — Atomic Macos Stealer Delivered Via Malvertising (report)
  • recordedfuture.com — Grayalpha Uses Diverse Infection Vectors Deploy Powernet Loader Netsupport Rat (report)
  • intrinsec.com — Tlp Clear From Espionage To Psyops Tracking Operations And Infrastructure Of Uacs In 2025 En 1 (report)
  • blog.sekoia.io — Privateloader The Loader Of The Prevalent Ruzki Ppi Service (report)
  • proofpoint.com — Security Brief Clickfix Social Engineering Technique Floods Threat Landscape (report)
  • Broadcom/Symantec — Malware Ai Llm (report)
  • elastic.co — Ghostpulse Haunts Victims Using Defense Evasion Bag O Tricks (report)
  • resource.redcanary.com — 2025Threatdetectionreport Redcanary (report)
  • blog.prevailion.com — The Curious Case Of Criminal Curriculum (report)
  • esentire.com — Fake Chrome Setup Leads To Netsupportmanager Rat And Mars Stealer (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Netsupportmanager Rat (report)
  • ptsecurity.com — Operation Ta505 Part2 (report)
  • bleepingcomputer.com — Hacked Steam Accounts Spreading Remote Access Trojan (report)
  • Trend Micro — New Opcjacker Malware Distributed Via Fake Vpn Malvertising (report)

External references