PULSE NAME
Fake Browser Update Campaign
WHITE Smartape SG/Haneymaney AlienVault 2024-03-28 Modified: 2024-04-27
13
IOCs
MEDIUM VOLUME
This report details a malware campaign distributing fake browser updates containing the NetSupport RAT remote access trojan. The attackers use staged web injections to ultimately download an executable payload which phones home to a command and control server.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
NetSupport RAT
Indicators of Compromise (2 / 13 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 c4f1b50e3111d29774f7525039ff7086 2024-03-28
FileHash-MD5 dc4c9430051fd1ee4993b091d778e130 2024-03-28