PULSE NAME
Unpacking NetSupport RAT Loaders Delivered via ClickFix
WHITE AlienVault 2025-10-24 Modified: 2025-11-23
108
IOCs
HIGH VOLUME
eSentire's Threat Response Unit observed multiple threat groups utilizing NetSupport Manager for malicious purposes throughout 2025. These groups have shifted from Fake Updates to ClickFix as their primary delivery method. The attack methodology involves social engineering victims to execute malicious commands in the Windows Run Prompt, leading to NetSupport extraction and execution. Three distinct threat groups were identified, each using different loaders and infrastructure. The groups are designated by their licensee names: EVALUSION, FSHGDREE32/SGI, and XMLCTL. The analysis includes details on the PowerShell/JSON-based loader, MSI-based loader, and NetSupport PCAP analysis. An unpacking utility and YARA rule are provided to aid researchers in detecting and analyzing NetSupport variants.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
NetSupport Manager
Indicators of Compromise (13 / 108 total)
All domain FileHash-MD5 FileHash-SHA1 FileHash-SHA256 CVE URL hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 1542df483ad5e2965fe768402eddae58 2025-10-24
FileHash-MD5 1c19c2e97c5e6b30de69ee684e6e5589 2025-10-24
FileHash-MD5 224bcc0a40cc43add82f5b03a11e59e3 2025-10-24
FileHash-MD5 290c26b1579fd3e48d60181a2d22a287 2025-10-24
FileHash-MD5 64f1310f6300870f1c81792733e92e5e 2025-10-24
FileHash-MD5 8bdcbba121984169948dfd09c629d6ae 2025-10-24
FileHash-MD5 9fe9416c45e183554e41fda8340e3338 2025-10-24
FileHash-MD5 beaac58fbfb2c65866cdf69cd785a48b 2025-10-24
FileHash-MD5 c4f1b50e3111d29774f7525039ff7086 2025-10-24
FileHash-MD5 cb08519e5cf5e95074c4d50bb4b87ca0 2025-10-24
FileHash-MD5 ee75b57b9300aab96530503bfae8a2f2 2025-10-24
FileHash-MD5 fce17b987f321dce852c8a52116e7eb6 2025-10-24
FileHash-MD5 2f0125ebef13328bfd11bcd6f3a0617a 2025-10-24