Js#smuggler Campaign is a threat campaign tracked across 1 threat cluster and 1 intelligence report mention on ThreatCluster. First observed December 8, 2025; most recent activity December 8, 2025.
JS#SMUGGLER Campaign is a threat campaign that leverages JavaScript-based delivery to smuggle the NetSupport RAT to visitors of infected websites. The use of NetSupport RAT—a full-featured remote access tool—highlights a shift toward web-delivered payloads that enable persistence, surveillance, and data exfiltration. This campaign underscores the ongoing abuse of web-compromise and JavaScript delivery chains to deploy remote access capabilities.
The JS#SMUGGLER campaign employs a three-step web attack to deliver the NetSupport RAT to Windows desktops. This attack utilizes obfuscated JavaScript and hidden HTA files, allowing hackers to gain full remote control…