Unpacking NetSupport RAT Loaders Delivered via ClickFix
Essential information
- Published
- 24/10/2025 04:30
- Modified
- 24/10/2025 09:45
- Tags
- 2025-10-24 clickfix netsupport rat remote administration tools
- Related entities
- 6 techniques (mitre), 1 malware, 7 others
Description
eSentire's Threat Response Unit observed multiple threat groups utilizing NetSupport Manager for malicious purposes throughout 2025. These groups have shifted from Fake Updates to ClickFix as their primary delivery method. The attack methodology involves social engineering victims to execute malicious commands in the Windows Run Prompt, leading to NetSupport extraction and execution. Three distinct threat groups were identified, each using different loaders and infrastructure. The groups are designated by their licensee names: EVALUSION, FSHGDREE32/SGI, and XMLCTL. The analysis includes details on the PowerShell/JSON-based loader, MSI-based loader, and NetSupport PCAP analysis. An unpacking utility and YARA rule are provided to aid researchers in detecting and analyzing NetSupport variants.