EXECUTIVE SUMMARY:
GrayAlpha, a cybercriminal group linked to FIN7, has been deploying a sophisticated malware campaign leveraging various infection vectors to deliver the PowerNet loader and NetSupport RAT. Their tactics involve impersonating popular software update pages and download portals to trick users into executing malicious payloads. The campaign uses multiple overlapping methods—including counterfeit browser updates, fake utility download sites, and a traffic distribution system (TDS)—to maximize reach. Researchers identified infrastructure tied to these operations, including domains registered using deceptive naming patterns.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
GrayAlpha, a cybercriminal group linked to FIN7, has been deploying a sophisticated malware campaign leveraging various infection vectors to deliver the PowerNet loader and NetSupport RAT. Their tactics involve impersonating popular software update pages and download portals to trick users into executing malicious payloads. The campaign uses multiple overlapping methods—including counterfeit browser updates, fake utility download sites, and a traffic distribution system (TDS)—to maximize reach. Researchers identified infrastructure tied to these operations, including domains registered using deceptive naming patterns.[emaillocker id="1283"]
GrayAlpha's infection chain uses three main methods. First, fake browser update pages mimic well-known services like Google and Zoom, running fingerprinting scripts to determine if a system is viable for infection. These redirect users to malicious domains where the PowerNet loader is dropped. Second, fake software sites trick users into downloading compromised installers, primarily for popular tools like 7-Zip. These sites use consistent delivery infrastructure and exploit bulletproof hosting services. Third, a TDS previously unseen in GrayAlpha activity—referred to as TAG-124—is used to drive traffic toward malware delivery endpoints. The PowerNet loader is a custom PowerShell script that unpacks and runs NetSupport RAT, while a second loader, MaskBat, shows connections to the FakeBat family, adding layers of obfuscation and persistence.
GrayAlpha's operation exemplifies the increasing of financially motivated threat actors. By employing multi-pronged delivery techniques, custom loaders, and resilient hosting infrastructure, they demonstrate strong operational discipline and adaptability. This campaign reflects the broader trend of professional cybercriminals using modular malware, evasion techniques, and advanced delivery systems to maintain long-term access to compromised systems. Effective defense against such threats requires a combination of user awareness, endpoint hardening, threat intelligence, and detection capabilities using behavioral indicators and threat-hunting strategies. Organizations must adapt by enhancing visibility, updating security baselines, and responding rapidly to anomalous activity linked to malware like PowerNet and NetSupport RAT.
THREAT PROFILE:
| Tactic | Technique ID | Technique | Sub-technique |
| Reconnaissance | T1595.002 | Active Scanning | Vulnerability Scanning |
| Resource Development | T1583.001 | Acquire Infrastructure | Domains |
| T1584.001 | Compromise Infrastructure | Domains | |
| Initial Access | T1566.002 | Phishing | Spear phishing Link |
| T1189 | Drive-by Compromise | — | |
| T1190 | Exploit Public-Facing Application | — | |
| Execution | T1059.001 | Command and Scripting Interpreter | PowerShell |
| T1204.002 | User Execution | Malicious File | |
| Persistence | T1547.001 | Boot or Logon Autostart Execution | Registry Run Keys / Startup Folder |
| T1053.005 | Scheduled Task/Job | Scheduled Task | |
| Privilege Escalation | T1055.001 | Process Injection | Dynamic-link Library Injection (DLL Injection) |
| Defence Evasion | T1027 | Obfuscated Files or Information | — |
| T1562.001 | Impair Defenses | Disable or Modify Tools | |
| Credential Access | T1555.003 | Credentials from Password Stores | Credentials from Web Browsers |
| Discovery | T1082 | System Information Discovery | — |
| Lateral Movement | T1021.001 | Remote Services | Remote Desktop Protocol (RDP) |
| Collection | T1113 | Screen Capture | — |
| T1056.001 | Input Capture | Keylogging | |
| Command and Control | T1219 | Remote Access Software | NetSupport RAT |
| T1071.001 | Application Layer Protocol | Web Protocols (HTTP/S) | |
| Exfiltration | T1041 | Exfiltration Over C2 Channel | — |
| Impact | T1499.004 | Endpoint Denial of Service | Application or System Exploitation |
REFERENCES:
The following reports contain further technical details:
[/emaillocker]