NetSupport RAT is a malware family tracked across 16 threat clusters and 31 intelligence report mentions on ThreatCluster. First observed November 13, 2025; most recent activity June 18, 2026.
The SmartApeSG campaign employs a fake CAPTCHA page and ClickFix script to deliver various remote access trojans (RATs) including Remcos, NetSupport, StealC, and Sectop RAT. The attack begins with Remcos RAT, which…
A new cyber threat identified by Huntress involves a fake background removal website that tricks users into executing malicious commands. Dubbed BackgroundFix, this site masquerades as a free image-editing service,…
On May 14, 2026, the SmartApeSG threat actor launched a supply chain attack by injecting malicious JavaScript into the Okendo Reviews widget, which is used by over 18,000 brands. This compromise allowed the delivery of…
The WantToCry ransomware campaign exploits exposed Server Message Block (SMB) services to remotely encrypt files without deploying malware on victim systems. Attackers scan for open SMB ports and use brute-force methods…
The SmartApeSG campaign, also known as ZPHP and HANEYMANEY, has been observed delivering multiple remote access trojans (RATs) including Remcos RAT, NetSupport RAT, StealC, and Sectop RAT (ArechClient2) through a social…
Matanbuchus 3.0, a C++-based downloader offered as Malware-as-a-Service since 2020, was identified in July 2025. This version introduces Protobuf-based serialization, ChaCha20 encryption, and enhanced anti-analysis…
The Bloody Wolf hacking group has been identified using fake government emails and weaponized PDFs to deploy the NetSupport Remote Access Trojan (RAT). This advanced persistent threat (APT) targets various organizations…
LummaStealer infections have surged due to social engineering campaigns utilizing the ClickFix technique to distribute CastleLoader malware. This infostealer, operating as a malware-as-a-service platform, had previously…
GrayCharlie, a threat actor, has been embedding malicious JavaScript into WordPress sites since mid-2023 to deliver the NetSupport RAT and Stealc malware to users. This group is associated with the SmartApeSG cluster…
The JS#SMUGGLER malware campaign has been identified, utilizing a multi-stage attack to deliver the NetSupport RAT, allowing attackers to gain covert control over victim computers. The attack begins with a JavaScript…