HomeSecurityNetSupport RAT: Attacks on government and educational organizations

NetSupport RAT: Attacks on government and educational organizations

Cybercriminals are targeting organizations in the education, government , and business sectors with a remote access trojan, called NetSupport RAT.

NetSupport RAT

The NetSupport RAT’s delivery mechanisms include fake updates, drive-by downloads, the use of malware loaders (such as GHOSTPULSE), and various forms of phishing,” VMware Carbon Black researchers said in a report seen by The Hacker News.

Researchers have identified at least 15 new infections related to the NetSupport RAT in recent weeks.

While NetSupport Manager started out as a legitimate remote administration tool for technical assistance and support, there are cybercriminals who have used it to carry out attacks.

See also: “Meal Kits” Malware Used for RAT Attacks

NetSupport RAT is usually downloaded to the device via deceptive websites and fake browser updates.

In August 2022, security firm Sucuri reported an attack that used compromised WordPress websites to display fraudulent protection . The goal was to distribute the NetSupport RAT.

Also, the use of fake browser updates can be effective and has in fact been used by many cybercriminals to distribute malware. For example, fake updates have been used to develop a JavaScript-based downloader malware, known as SocGholish. This distributed another loader malware codenamed BLISTER.

NetSupport RAT: Attacks on government and educational organizations

The Javascript payload is then linked to PowerShell to connect to a remote server and retrieve a ZIP archive file containing the NetSupport RAT.

See also: LittleDrifter malware: Gamaredon hackers' new worm targets Ukraine

According to security researchers, once installed on a victim's computer, NetSupport is able to monitor user, transfer files, manipulate computer settings, and move to other devices within the network.

Protection

One of the key measures that users and organizations can take to protect themselves from NetSupport RAT is awareness and education about the existence of this malware and the methods it uses to infiltrate systems. Also, training on how to recognize suspicious emails and attachments can be an effective preventative measure.

Additionally, installing up-to-date antivirus software and regularly updating operating systems and applications is essential to detect and prevent NetSupport RAT infections. Also, using multi-layered security, with advanced firewall protection and access rights restrictions, can limit the malware attack.

See also: Russian hackers APT29 use WinRAR exploit to attack embassies

Finally, regularly backing up data and storing it in a secure location can be an effective recovery measure in the event of infections. Overall, the combined use of these measures can help organizations protect themselves from NetSupport RAT infections.

Source: thehackernews.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS