NetSupport RAT

General News

Summary

Although NetSupport Manager initially served as a legitimate remote administration tool designed for technical support, it has been viciously repurposed by threat actors. The deployment of counterfeit web browser updates is a strategy commonly linked to the utilization of a JavaScript-based downloader malware called SocGholish (also known as FakeUpdates). The JavaScript payload then triggers PowerShell to establish a connection with a remote server, fetching a ZIP archive file containing the NetSupport RAT. Attackers can monitor keystrokes, capture screenshots, access files, and even activate webcams and microphones, leading to a severe invasion of privacy. Overall, the combination of stealth, persistence, and the broad range of capabilities associated with RATs makes them particularly dangerous and a significant concern for cybersecurity professionals and organizations.

Classifications

industries
Entertainment
applications
Customer Service & Support

AskAI Classifications

Labels
Cybersecurity Software Anti-Malware Software SaaS Security

Linked Companies

EnigmaSoft
$1M to $5M