216.73.216.6

Unpacking NetSupport RAT Loaders Delivered via ClickFix

· Published 24/10/2025 04:30 · Modified 24/10/2025 09:45

Export JSON

Essential information

Published
24/10/2025 04:30
Modified
24/10/2025 09:45
Tags
2025-10-24 clickfix netsupport rat remote administration tools
Related entities
6 techniques (mitre), 1 malware, 7 others

Description

eSentire's Threat Response Unit observed multiple threat groups utilizing NetSupport Manager for malicious purposes throughout 2025. These groups have shifted from Fake Updates to as their primary delivery method. The attack methodology involves social engineering victims to execute malicious commands in the Windows Run Prompt, leading to NetSupport extraction and execution. Three distinct threat groups were identified, each using different loaders and infrastructure. The groups are designated by their licensee names: EVALUSION, FSHGDREE32/SGI, and XMLCTL. The analysis includes details on the PowerShell/JSON-based loader, MSI-based loader, and NetSupport PCAP analysis. An unpacking utility and YARA rule are provided to aid researchers in detecting and analyzing NetSupport variants.

External references