Threat Advisory

GrayAlpha Deploys PowerNet Loader via Deceptive Vectors

Threat: Malicious Campaign
Threat Actor Name: GrayAlpha
Threat Actor Type: Financially Motivated
Targeted Region: Global
Alias: G0046, FIN 7,Carbon Spider,Elbrus,Sangria,Tempest,Carbanak,Calcium,Coreid,TAG-CR1,ITG14,Gold Niagara,ATK32,APT-C-11,Navigator,Gold Waterfall,ELBRUS,G0008,TelePort Crew, Magecart Group 7
Threat Actor Region: Global
Targeted Sector: Technology & IT, Finance & Banking, Retail & E-commerce
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

GrayAlpha, a cybercriminal group linked to FIN7, has been deploying a sophisticated malware campaign leveraging various infection vectors to deliver the PowerNet loader and NetSupport RAT. Their tactics involve impersonating popular software update pages and download portals to trick users into executing malicious payloads. The campaign uses multiple overlapping methods—including counterfeit browser updates, fake utility download sites, and a traffic distribution system (TDS)—to maximize reach. Researchers identified infrastructure tied to these operations, including domains registered using deceptive naming patterns.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

GrayAlpha, a cybercriminal group linked to FIN7, has been deploying a sophisticated malware campaign leveraging various infection vectors to deliver the PowerNet loader and NetSupport RAT. Their tactics involve impersonating popular software update pages and download portals to trick users into executing malicious payloads. The campaign uses multiple overlapping methods—including counterfeit browser updates, fake utility download sites, and a traffic distribution system (TDS)—to maximize reach. Researchers identified infrastructure tied to these operations, including domains registered using deceptive naming patterns.[emaillocker id="1283"]

GrayAlpha's infection chain uses three main methods. First, fake browser update pages mimic well-known services like Google and Zoom, running fingerprinting scripts to determine if a system is viable for infection. These redirect users to malicious domains where the PowerNet loader is dropped. Second, fake software sites trick users into downloading compromised installers, primarily for popular tools like 7-Zip. These sites use consistent delivery infrastructure and exploit bulletproof hosting services. Third, a TDS previously unseen in GrayAlpha activity—referred to as TAG-124—is used to drive traffic toward malware delivery endpoints. The PowerNet loader is a custom PowerShell script that unpacks and runs NetSupport RAT, while a second loader, MaskBat, shows connections to the FakeBat family, adding layers of obfuscation and persistence.

GrayAlpha's operation exemplifies the increasing of financially motivated threat actors. By employing multi-pronged delivery techniques, custom loaders, and resilient hosting infrastructure, they demonstrate strong operational discipline and adaptability. This campaign reflects the broader trend of professional cybercriminals using modular malware, evasion techniques, and advanced delivery systems to maintain long-term access to compromised systems. Effective defense against such threats requires a combination of user awareness, endpoint hardening, threat intelligence, and detection capabilities using behavioral indicators and threat-hunting strategies. Organizations must adapt by enhancing visibility, updating security baselines, and responding rapidly to anomalous activity linked to malware like PowerNet and NetSupport RAT.

THREAT PROFILE:

Tactic Technique ID Technique Sub-technique
Reconnaissance T1595.002 Active Scanning Vulnerability Scanning
Resource Development T1583.001 Acquire Infrastructure Domains
T1584.001 Compromise Infrastructure Domains
Initial Access T1566.002 Phishing Spear phishing Link
T1189 Drive-by Compromise
T1190 Exploit Public-Facing Application
Execution T1059.001 Command and Scripting Interpreter PowerShell
T1204.002 User Execution Malicious File
Persistence T1547.001 Boot or Logon Autostart Execution Registry Run Keys / Startup Folder
T1053.005 Scheduled Task/Job Scheduled Task
Privilege Escalation T1055.001 Process Injection Dynamic-link Library Injection (DLL Injection)
Defence Evasion T1027 Obfuscated Files or Information
T1562.001 Impair Defenses Disable or Modify Tools
Credential Access T1555.003 Credentials from Password Stores Credentials from Web Browsers
Discovery T1082 System Information Discovery
Lateral Movement T1021.001 Remote Services Remote Desktop Protocol (RDP)
Collection T1113 Screen Capture
T1056.001 Input Capture Keylogging
Command and Control T1219 Remote Access Software NetSupport RAT
T1071.001 Application Layer Protocol Web Protocols (HTTP/S)
Exfiltration T1041 Exfiltration Over C2 Channel
Impact T1499.004 Endpoint Denial of Service Application or System Exploitation

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu