Summary:
In recent years, threat actors have repurposed this software as a Remote Access Trojan (RAT) to enter systems and use them as a launching pad for subsequent attacks. Researchers observed that the majority of problems originated from the government, business services, and education sectors based on the growth. File transfers, support chat, inventory management, and remote access were all made possible by this program. The NetSupport RAT is distributed through a variety of methods, including drive-by downloads, phishing campaigns, malware loaders like GhostPulse, and fake upgrades. Since NetSupport Manager is widely accessible and legal, it is not limited to a single threat actor. Multiple criminal apparel, including the notorious TA569 - known for its SocGholish virus - use this technology in their arsenal.[/subscribe_to_unlock_form]
Summary:
In recent years, threat actors have repurposed this software as a Remote Access Trojan (RAT) to enter systems and use them as a launching pad for subsequent attacks. Researchers observed that the majority of problems originated from the government, business services, and education sectors based on the growth. File transfers, support chat, inventory management, and remote access were all made possible by this program. The NetSupport RAT is distributed through a variety of methods, including drive-by downloads, phishing campaigns, malware loaders like GhostPulse, and fake upgrades. Since NetSupport Manager is widely accessible and legal, it is not limited to a single threat actor. Multiple criminal apparel, including the notorious TA569 - known for its SocGholish virus - use this technology in their arsenal.[emaillocker id="1283"]
Recent attacks have shown that fake browser upgrades and misleading websites can download the NetSupport RAT onto a victim's computer. A PHP script on these compromised websites shows what appears to be an official update. An extra Javascript payload is delivered to the endpoint when the victim hits the download link. After executing obfuscated commands with powershell.exe, Update_browser_10.6336.js establishes a connection to kgscrew[.]com. After passing a Base64 sample via memory, Powershell.exe decodes it and saves the contents in a file. This decompressed file contains the NetSupport Manager and other NetSupport dependencies/DLLs.After being installed on a victim's device, NetSupport can go to other devices connected to the network, transfer files, change computer settings, and observe behavior.
After that, PowerShell is used to launch client32.exe, a NetSupport application, which is used to run the PowerShell script and establish a connection to the Command-and-Control server of Netsupport RAT. In order to download extra payloads, researchers have also discovered a URL that is provided to the DownloadString function. The payload is downloaded when an impacted endpoint connects to the compromised URL via the network.
The NetSupport Remote Access Trojan (RAT) has become a serious concern because it uses trustworthy software for malicious aims in a number of industries, including government, business services, and education. The NetSupport RAT poses a major risk due to its ability to infect legitimate software, spread covertly throughout networks, and perform a variety of intrusive behaviors, needing powerful cybersecurity measures to detect, prevent, and limit its impact.
Threat Profile:

References:
The following reports contain further technical details:
https://thehackernews.com/2023/11/netsupport-rat-infections-on-rise.html
[/emaillocker]