www.recordedfuture.com
GrayAlpha Threat Actor Uses MaskBat Loader for NetSupport RAT Deployments
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Insikt Group identified GrayAlpha, a threat actor linked to FIN7, utilizing a custom loader named MaskBat to deploy NetSupport RAT through various infection vectors. These include fake browser update pages, fake 7-Zip download sites, and the TAG-124 traffic distribution system. The fake browser update lures impersonate legitimate services like Google Meet and CNN. GrayAlpha's operations have been active since at least April 2024, with new domains emerging as recently as April 2025. The simultaneous use of multiple infection vectors highlights the group's evolving tactics. Security professionals are advised to implement application allow-lists and conduct comprehensive employee training to recognize suspicious activity. Detection rules and monitoring of network artifacts are also recommended to combat these threats. The report emphasizes the increasing professionalization of cybercrime, necessitating an adaptive security posture.
Key Points: • GrayAlpha, linked to FIN7, employs MaskBat to deliver NetSupport RAT. • Infection vectors include fake browser updates and fake 7-Zip downloads. • Defenders should enforce application allow-lists and enhance employee training.