Some hackers designed a website that mimics the Pokemon NFT card game to spread the NetSupport remote access tool, allowing them to gain unauthorized control over victims' devices.

The website “pokemon-go[.]io,” which is still online at the time of writing, claims to host a new NFT card game created around the Pokemon franchise, offering users entertainment along with profits from NFT investments.
See also: Hackers stole Slack's private GitHub code repositories
With the immense popularity of both Pokemon and NFTs, it is very likely that the operators behind the malicious portal have no problem attracting victims through spam messages or social media posts .

Clicking the “Play on PC” button will download a file that appears to be a genuine game installer, but in reality installs the NetSupport Remote Access Tool (RAT) on system .
ASEC analysts identified the malicious operation and revealed that a second website had previously been used in this campaign – “beta-pokemoncards[.]io” – but has since been taken down.
In December 2022, the first evidence of the presence of this campaign appeared, and further investigative research on VirusTotal revealed that the same operators had promoted a fake Visual Studio file instead of the Pokemon game.
See also: Hacker: Lukashenko did not take a COVID-19 PCR test before meeting with Putin
NetSupport RAT Drop
The NetSupport RAT executable file (“client32.exe”) and its dependencies are secretly installed in a folder within the %APPDATA% path, with each file set to “hidden” to avoid detection by victims manually inspecting the directory structure.

Additionally, the installer creates an entry in the Windows Startup folder to guarantee that when your device is turned on, the RAT.
As NetSupport Manager is a legitimate application, malicious actors commonly use it to evade detection by security software.

Hackers now have the ability to remotely connect to a person's device and steal data, install additional malware, or even attempt to spread further across a network.
Although NetSupport Manager is a reliable and legitimate software product, it is unfortunately often abused by malicious actors to carry out their malicious activities.
In 2020, Microsoft warned the public about malicious actors using COVID-19-themed Excel files to drop the NetSupport RAT on unsuspecting victims' computers.
In August 2022, a malicious attack was launched against WordPress websites and installed the NetSupport RAT and the infamous Raccoon Stealer via fake Cloudflare DDoS protection pages .
See also: Play ransomware responsible for Rackspace attack
NetSupport Manager offers a range of connectivity solutions, including network traffic encryption, as well as remote screen control, monitoring and system for easy management. It also supports the ability to group systems remotely, so you have better control over your environment.
As a result of the infection, users face serious consequences, such as unauthorized access to sensitive data and downloading additional malware.
As you can see, non-fungible tokens have become increasingly popular in recent years due to their unique features and various advantages over traditional methods of trading digital assets.
Information source: bleepingcomputer.com
