A new phishing campaign is targeting US organizations with the aim of infecting them with the NetSupport RAT.

Israeli cybersecurity Perception Point is monitoring the campaign codenamed Operation PhantomBlu.
“ The PhantomBlu operation introduces a differentiated exploitation method that deviates from the typical NetSupport RAT delivery mechanism by leveraging OLE (Object Linking and Embedding) template manipulation, exploiting Microsoft Office document templates to execute malicious code ,” said security researcher Ariel Davidpur .
NetSupport RAT is a malicious offshoot of the legitimate remote desktop tool NetSupport Manager. The RAT allows attackers to do a variety of things, including steal data.
See also: PixPirate banking trojan targets users in Brazil
The attack begins with a phishing email about an employee’s salary. The email purports to come from the accounting department and urges recipients to open the attached Microsoft Word document to view the “monthly salary report.”
A closer analysis of the email – particularly the Return-Path and Message-ID fields – shows that the attackers behind the NetSupport RAT are using a legitimate email marketing platform called Brevo (formerly Sendinblue).
Upon opening, the Word document instructs the victim to enter a password provided in the body of the email. They are also asked to enable editing and double-click a printer icon embedded in the document.
See also: WogRAT malware: Targeting Windows and Linux and aNotepad abuse
If the user follows these steps, they will open a ZIP archive file (“Chart20072007.zip”) containing a Windows, which acts as a PowerShell dropper to retrieve and execute the NetSupport RAT from a remote server.
“By using encrypted .docs to deliver the NetSupport RAT via OLE template and template injection, the PhantomBlu operation marks a departure from the conventional TTPs associated with NetSupport RAT deployments,” Davidpur said, adding that the new technique “demonstrates PhantomBlu’s innovation in combining sophisticated evasion techniques with social engineering.”

NetSupport RAT Malware
To avoid such attacks, organizations can strengthen the security of their networks by using advanced security that provide protection against malware and phishing attacks.
See also: Bifrost RAT: New Linux version mimics VMware domain
It is important to train their staff in recognizing and avoiding phishing attacks, teaching them how to recognize suspicious emails and links.
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Additionally, they can use software that provides protection against the execution of malicious processes and the installation of trojans, such as NetSupport RAT.
Finally, using policies to restrict access to sensitive systems and data can help prevent the spread of malware in the event that a system is compromised.
Source: thehackernews.com
