Skip to main content

Threats Tagged 'netsupport manager'

View all threats tagged with 'netsupport manager'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: netsupport manager

Threats Tagged 'netsupport manager'

Click on any threat for detailed analysis and mitigation recommendations

Cisco Talos identified a malware infection chain leveraging WebDAV-based DLL execution to deliver the Amatera stealer along with secondary payloads ZigCryptoStealer and NetSupport Manager. The infection uses a Cloudflare Worker to inject JavaScript stored on the BNB Smart Chain blockchain and employs a fake CAPTCHA prompt to trick victims into executing malware. Two distinct DLL loaders, "verification.google" and "pf.ch", deploy different secondary payloads. The "verification.google" loader installs NetSupport Manager with a command-and-control server IP linked to Russia, suggesting a Russian threat actor. The infection was first observed in April 2026 targeting a Ukrainian government organization but is assessed as not specifically targeted. The threat involves credential and cryptocurrency theft through sophisticated multi-stage delivery mechanisms.

Join the discussion

A sophisticated infection chain leverages PowerShell loaders to deliver encrypted NetSupport client payloads concealed within fake MP4 files. The malicious MP4 containers appear valid to basic file-type checks but contain 6.5 MB of encrypted data in ISO Base Media File Format uuid extension boxes rather than playable video content. The attack begins with PowerShell delivered via Cloudflare-fronted infrastructure, performing environment checks before retrieving the carrier file. A secondary script parses the MP4 structure, extracts and decrypts an embedded 16.8 MB PowerShell payload, then deploys NetSupport Manager with silent operation configured. Infrastructure spans 40 live endpoints across six autonomous systems, primarily in Frankfurt and Los Angeles, with command-and-control gateways registered 77 seconds apart. The toolkit employs Russian-language business site decoys and rotates carriers frequently without backward compatibility.

Join the discussion

Following Black Hat and DEF CON conferences, a threat actor targeted attendees through X direct messages, posing as CoinDesk's VP and Head of Marketing to establish trust under the pretext of conference planning. The campaign employed a malicious Google Apps Script embedded in a Google Doc that presented ClickFix-style instructions and manual download options. The attack delivered different payloads based on the victim's operating system: macOS users received AMOS infostealer, while Windows users were infected with NetSupport RAT, a Ledger wallet implant, and a TLS-intercepting proxy. A secondary lure masqueraded as a DocSend installer to deliver additional payloads. The operation demonstrated sophisticated social engineering by leveraging trusted platforms and post-conference networking expectations.

Join the discussion

In May and June 2026, the Clubfoot Wolf cluster executed a large-scale phishing campaign targeting Russian organizations across manufacturing, retail, e-commerce, agriculture, IT, transportation, healthcare, and science sectors, with primary focus on wholesale distributors of chemical products. Several Belarusian organizations were also compromised. The adversary sent phishing emails disguised as invoices or purchase requests, containing ZIP archives with decoy documents and malicious LNK files. Upon execution, a PowerShell script downloaded and installed NetSupport Manager, a legitimate remote administration tool, which was then used for malicious activities. The attackers employed URL shorteners to hide infrastructure and used multiple decoy files to build victim trust. The campaign demonstrated continuous evolution in delivery methods and infection chains.

Join the discussion
0

A Microsoft Teams voice-phishing campaign leveraging Quick Assist, a remote administration tool, was tracked in September 2025. The campaign uses help desk scams to gain initial access, followed by user group enumeration and the execution of a PowerShell script to download a command and control payload. The attack employs AMSI bypass, encrypted communications, and a web-socket remote access trojan. Multiple Microsoft 365 tenants with IT-related subdomains were used, along with various IPs and domains for C2 infrastructure. The campaign shows similarities to Storm-1811 and PhantomCaptcha activities, suggesting a complex cybercrime ecosystem. The attackers' ultimate goal may be ransomware deployment, although observed attempts were successfully blocked.

Join the discussion

Showing 1 to 5 of 5 results

Filters:Tag: netsupport manager
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses