#NetSupportRAT
ISC diary: #SmartApeSG campaign uses #ClickFix page to push #NetSupportRAT https://isc.sans.edu/diary/32474
November 12, 2025 at 9:51 PM
2024-12-13 (Friday): www.anceltech[.]com compromised with #SmartApeSG leading to #NetSupport #RAT 2 injected scripts. jitcom[.]info and best-net[.]biz.

Pivoting on best-net[.]biz in URLscan show signs of six other compromised sites: urlscan.io/search/#best...

#NetSupportRAT
December 13, 2024 at 6:56 PM
2025-07-17 (Thursday): Tracking the #SmartApeSG campaign for #ClickFix pages pushing #NetSupportRAT. Details at github.com/malware-traf...
July 17, 2025 at 2:09 PM
2025-07-15 (Tuesday): Some different IOCs from the #SmartApeSG #ClickFix page today.

warpdrive[.]top <-- domain used for SmartAgeSG injected script and to display ClickFix page.

sos-atlanta[.]com <-- domain from script injected into clipboard and to retrieve #NetSupportRAT malware package
July 15, 2025 at 7:18 PM
Post I wrote for my employer on other social media:

2025-02-18 (Tues): Legit but compromised websites with injected script for #SmartApeSG lead to a fake browser update for #NetSupportRAT malware. During an infection run, we saw follow-up malware for #StealC. Details at github.com/PaloAltoNetw...
February 19, 2025 at 4:01 PM
ISC Diary: #SmartApeSG campaign pushes #Remcos #RAT, #NetSupportRAT, #StealC and #SectopRAT (#ArechC https://isc.sans.edu/diary/32826
March 25, 2026 at 7:15 AM
2024-12-11 (Wednesday): Zip archive containing #NetSupport #RAT hosted at hxxps[:]//homeservicephiladelphia[.]info/work/yyy.zip

C2 for this NetSupport package is 194.180.191[.]64, which is a known NetSupport C2 active since 2024-11-22, per ThreatFox: threatfox.abuse.ch/ioc/1346763/

#NetSupportRAT
December 11, 2024 at 6:39 PM
2025-09-22 (Monday) #SmartApeSG campaign using #FileFix style #ClickFix technique on its fake CAPTCHA page for #NetSupportRAT. Script sent to victim through #clipboardhijacking downloads MSI from founderevo[.]com/res/velvet when pasted into a File Manager window (www.virustotal.com/gui/file/958...)
September 22, 2025 at 7:20 PM
New JS#SMUGGLER malware campaign delivers #NetSupportRAT through compromised websites – hackers get full remote control of Windows machines.

Read: hackread.com/jssmuggler-n...

#JSsmuggler #Malware #Cybersecurity #Windows
New JS#SMUGGLER Campaign Drops NetSupport RAT Through Infected Sites
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
hackread.com
December 8, 2025 at 6:26 PM
2025-06-18 (Wed): #SmartApeSG --> #ClickFix lure --> #NetSupportRAT --> #StealCv2

A #pcap of the traffic, the malware/artifacts, and some IOCs are available at www.malware-traffic-analysis.net/2025/06/18/i....

Today's the 12th anniversary of my blog, so I made this post a bit more old school.
June 19, 2025 at 4:23 AM
2025-08-20 (Wed): #SmartApeSG for fake #CAPTCHA page with #ClickFix instructions that led to an MSI file for #NetSupport #RAT and the #NetSupportRAT infection led to #StealCv2. Malware samples, a #pcap, and indicators at www.malware-traffic-analysis.net/2025/08/20/i...
August 20, 2025 at 11:21 PM
2024-12-17 (Tues): #SmartApeSG injected script leads to fake browser update page that leads to #NetSupport #RAT infection. A #pcap of the infection traffic, associated malware samples and more information is available at www.malware-traffic-analysis.net/2024/12/17/i...

#FakeUpdates #NetSupportRAT
December 17, 2024 at 4:57 AM
2025-07-22 (Tuesday): Tracking the #SmartApeSG campaign using #ClickFix to push #NetSupportRAT. Details at: github.com/malware-traf...
July 22, 2025 at 6:58 PM
2025-07-14 (Monday): #SmartApeSG script injected into page from compromised website leads to #ClickFix style fake verification page. ClickFix-ing you way through this leads to a #NetSupportRAT infection.
July 14, 2025 at 11:22 PM
June 27, 2025 at 7:13 PM
BLOG POST: A write-up on some infrastructure we were tracking during 2024, connected to both SmartApeSG and NetSupportRAT activities. They do usually follow one another around but we've exposed direct links from a management and oversight perspective.

www.team-cymru.com/post/tracing...
Uncovering Cyber Threat Networks: SmartApeSG & NetSupport RAT | Cymru
Explore how Internet telemetry analysis exposed hidden cyber threat connections between SmartApeSG, NetSupport RAT, Quasar RAT, and cryptocurrency scams. Request a demo!
www.team-cymru.com
February 4, 2025 at 1:29 PM
6/ TAG-150 also deploys other malware families, including #SectopRAT, #WarmCookie, #HijackLoader, and #NetSupportRAT, as well as numerous stealers: #Stealc, #RedLine, #Rhadamanthys, #DeerStealer, #MonsterV2, and more.
September 4, 2025 at 3:05 PM
Il tuo sito WordPress non è una vetrina: è già una botnet (GrayCharlie docet)

📌 Link all'articolo : www.redhotcyber.com/post/il-...

#redhotcyber #news #cybersecurity #hacking #malware #ransomware #netsupportrat #wordpress #javascript
January 19, 2026 at 2:52 PM
Beware of the evolving SmartApeSG campaign using the ClickFix technique to deploy NetSupport RAT via fake CAPTCHA prompts. Stay vigilant and educate users on these deceptive tactics. #CyberSecurity #ClickFix #NetSupportRAT Link: thedailytechfeed.com/smartapesg-u...
November 15, 2025 at 6:24 PM
The latest blog post from Team Cymru's S2 Research Team demonstrates how exploring internet telemetry data can uncover interconnected threats - in this case, the link between SmarApeSG and NetSupportRat. www.team-cymru.com/post/tracing...
February 4, 2025 at 10:38 AM
2025-12-29 (Monday): #ClickFix page leads to #NetSupportRAT infection.

Details at www.malware-traffic-analysis.net/2025/12/29/i...
December 29, 2025 at 10:41 PM
A fake CoinDesk exec DMed a researcher post-DEF CON with a doc that drops AMOS and a RAT. https://intel.threadlinqs.com/threat/TL-2026-2449 #ThreatIntel #AMOS #NetSupport #NetSupportRAT
September 11, 2026 at 9:56 PM
📢 NetSupport RAT distribué via des liens ChatGPT légitimes et une fausse vérification Cloudflare

Article publié le 1er septembre 2026 sur Cyber Press, décrivant une campagne active de distribution de NetSupport RAT…

🟢 vérification factuelle haute
#NetSupportRAT #ChatGPTAbuse #Cyberveille
NetSupport RAT distribué via des liens ChatGPT légitimes et une fausse vérification Cloudflare
Article publié le 1er septembre 2026 sur Cyber Press, décrivant une campagne active de distribution de NetSupport RAT exploitant la confiance accordée aux pages partagées de ChatGPT.
cyberveille.ch
September 1, 2026 at 11:00 PM
📢 Des hackers abusent de liens ChatGPT et d'un faux CAPTCHA Cloudflare pour déployer NetSupport RAT

Cyber Press, publié le 1er septembre 2026. L'article décrit une campagne active de distribution de NetSupport RAT…

🟢 vérification factuelle haute
#NetSupportRAT #ChatGPTAbuse #Cyberveille
Des hackers abusent de liens ChatGPT et d'un faux CAPTCHA Cloudflare pour déployer NetSupport RAT
Cyber Press, publié le 1er septembre 2026. L'article décrit une campagne active de distribution de NetSupport RAT exploitant des mécanismes de confiance basés sur des plateformes légitimes. Les attaquants utilisent des pages de conversation partagées ChatGPT légitimes (chatgpt.com) comme premier vecteur de confiance.
cyberveille.ch
September 2, 2026 at 2:30 AM
CastleLoader malware now delivers NeedleStealer, a Rust crypto wallet spoofer and Golang browser hijacker. Arctic Wolf tracks three new campaigns.

#CastleLoader #NeedleStealer #Malware #InfoStealer #CryptoTheft #NetSupportRAT #ThreatIntel #InfoSec #CyberSecurity
CastleLoader Malware Now Delivers NeedleStealer Wallet and Browser Spoofers
At a glance
securityonline.info
August 3, 2026 at 6:13 AM