GrayAlpha Threat Actor Uses MaskBat Loader for NetSupport RAT Deployments

GrayAlpha Threat Actor Uses MaskBat Loader for NetSupport RAT Deployments

First seen 6 Aug 2026, 12:37 UTC Mallory.Aiwww.recordedfuture.comattack.mitre.org 88% similarity 69.5

Article Content

Browse articles
ThreatCluster

Insikt Group identified GrayAlpha, a threat actor linked to FIN7, utilizing a custom loader named MaskBat to deploy NetSupport RAT through various infection vectors. These include fake browser update pages, fake 7-Zip download sites, and the TAG-124 traffic distribution system. The fake browser update lures impersonate legitimate services like Google Meet and CNN. GrayAlpha's operations have been active since at least April 2024, with new domains emerging as recently as April 2025. The simultaneous use of multiple infection vectors highlights the group's evolving tactics. Security professionals are advised to implement application allow-lists and conduct comprehensive employee training to recognize suspicious activity. Detection rules and monitoring of network artifacts are also recommended to combat these threats. The report emphasizes the increasing professionalization of cybercrime, necessitating an adaptive security posture.

Key Points: • GrayAlpha, linked to FIN7, employs MaskBat to deliver NetSupport RAT. • Infection vectors include fake browser updates and fake 7-Zip downloads. • Defenders should enforce application allow-lists and enhance employee training.

ThreatCluster AI How this analysis works

Timeline

2024-04-01
GrayAlpha's fake browser updates identified
Fake browser update lures impersonating services like Google Meet were first observed.
Mallory.Ai
2025-04-01
New domains registered for infection vectors
Newly registered domains for fake 7-Zip download pages were identified, indicating ongoing operations.
RecordedFuture
2026-08-06
GrayAlpha infrastructure reported
Insikt Group published findings on GrayAlpha's use of MaskBat and various infection methods.
RecordedFuture

Community

Browse all →