Cybercriminals are targeting organizations in the education, government , and business sectors with a remote access trojan, called NetSupport RAT.

“The NetSupport RAT’s delivery mechanisms include fake updates, drive-by downloads, the use of malware loaders (such as GHOSTPULSE), and various forms of phishing,” VMware Carbon Black researchers said in a report seen by The Hacker News.
Researchers have identified at least 15 new infections related to the NetSupport RAT in recent weeks.
While NetSupport Manager started out as a legitimate remote administration tool for technical assistance and support, there are cybercriminals who have used it to carry out attacks.
See also: “Meal Kits” Malware Used for RAT Attacks
NetSupport RAT is usually downloaded to the device via deceptive websites and fake browser updates.
In August 2022, security firm Sucuri reported an attack that used compromised WordPress websites to display fraudulent protection . The goal was to distribute the NetSupport RAT.
Also, the use of fake browser updates can be effective and has in fact been used by many cybercriminals to distribute malware. For example, fake updates have been used to develop a JavaScript-based downloader malware, known as SocGholish. This distributed another loader malware codenamed BLISTER.

The Javascript payload is then linked to PowerShell to connect to a remote server and retrieve a ZIP archive file containing the NetSupport RAT.
See also: LittleDrifter malware: Gamaredon hackers' new worm targets Ukraine
According to security researchers, once installed on a victim's computer, NetSupport is able to monitor user, transfer files, manipulate computer settings, and move to other devices within the network.
Protection
One of the key measures that users and organizations can take to protect themselves from NetSupport RAT is awareness and education about the existence of this malware and the methods it uses to infiltrate systems. Also, training on how to recognize suspicious emails and attachments can be an effective preventative measure.
Additionally, installing up-to-date antivirus software and regularly updating operating systems and applications is essential to detect and prevent NetSupport RAT infections. Also, using multi-layered security, with advanced firewall protection and access rights restrictions, can limit the malware attack.
See also: Russian hackers APT29 use WinRAR exploit to attack embassies
Finally, regularly backing up data and storing it in a secure location can be an effective recovery measure in the event of infections. Overall, the combined use of these measures can help organizations protect themselves from NetSupport RAT infections.
Source: thehackernews.com
