HomeSecurityClickFix techniques used to install NetSupport RAT loaders

Using ClickFix techniques to install NetSupport RAT loaders

Cybercriminals continue to evolve their tactics, shifting their focus from traditional phishing scams to more targeted social engineering attacks. Throughout 2025, threat actors adopted the ClickFix, using fake pages to trick users into running PowerShell commandsthat install NetSupport Manager, a legitimate remote administration tool that is now being used by hackers to gain unauthorized access.

ClickFix NetSupport

Multi-stage infection chain

The attack begins with deceptive ClickFix pages, which ask the victim to execute commands. Once the command is executed, a multi-stage infection process: PowerShell-based loaders download encoded JSON blobs from attacker-controlled servers, decode the payloads, and install NetSupport on the system. eSentire have identified at least three independent groups using this method, confirming that the technique has been widely adopted.

See also: Hackers target sites through outdated WordPress plugins

Hiding and persistence techniques

Loaders use multi-layered concealment techniques:

  • Base64 encoding for JSON blobs.
  • Installing secondary loaders via MSI packages executed with msiexec.
  • Create hidden folders and shortcuts in %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup.
  • Delete RunMRU to make analysis more difficult.

This level of operational security increases the success rates of attacks and reduces the chances of detection by static security mechanisms.

Using ClickFix techniques to install NetSupport RAT loaders

The risks for businesses

ClickFix attacks don't just target a user's computer. Attackers gain remote control, maintain persistence, and can:

  • Check and modify critical files.
  • Execute commands on corporate networks.
  • They steal sensitive data.
  • Install further malware.

Exploiting the human factor makes attacks particularly effective, as employees follow misleading instructions to solve seemingly "technical problems."

See also: Hackers steal Discord accounts via RedTiger

Using ClickFix techniques to install NetSupport RAT loaders

Protection measures

Organizations must implement technical and organizational measures:

  • Whitelist applications to restrict MSI and PowerShell execution.
  • Monitoring for base64 decoding, flags like -nop and -ep Bypass , and non-standard msiexec executions.
  • Continuous monitoring of logs and SIEM rules for chained executions and abnormal network traffic.

Safety training and culture

User training remains critical. Employees must:

  • They avoid executing commands from unverified pages.
  • They recognize suspicious ClickFix prompts.
  • They immediately contact IT departments in suspicious incidents.

Incident handling

In case of infection:

  • Isolate affected systems immediately.
  • Perform a full analysis.
  • Implement incident response playbooks.
  • Report incidents to authorities and work with cloud providers to restrict C2 servers.

See also: New phishing campaign targets LastPass users

The new reality of cybercrime

The ClickFix attacks demonstrate that criminals are organized and exploiting legitimate tools for malicious purposes. Protection requires a combination of technology, education, and information sharing. Continuous monitoring, strict policy enforcement, and red team exercises drastically reduce the risk of these sophisticated attacks succeeding.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS