The SANS ISC diary on an unidentified RAT pushing NetSupport RAT is a good reminder that ClickFix campaigns are becoming a reliable malware delivery method. In this case, the infection originated from the SmartApeSG ClickFix campaign, where a fake verification page instructed users to run commands that eventually led to an initial RAT infection, followed by deployment of a malicious NetSupport Manager RAT package.
This is especially dangerous because NetSupport Manager is a legitimate remote administration tool, but attackers abuse it for persistence, remote control, and hands-on-keyboard activity. The diary notes that the unidentified initial RAT generated encoded command-and-control traffic to 89.110.110[.]119 over TCP port 443, and later delivered NetSupport RAT components through follow-up C2 activity. Legitimate tools being used maliciously is the attacker’s favorite costume party, and sadly, it keeps working.
Organizations should monitor for fake verification or ClickFix-style pages, unusual command execution after browser activity, unexpected VBS or batch files in C:\ProgramData, suspicious NetSupport installations, and outbound traffic to unknown infrastructure over port 443 that is not actually HTTPS/TLS. Security teams should also review endpoint telemetry for files such as processor.vbs, token.bat, setup.cab, and unexpected extraction into C:\ProgramData\UpdateInstaller\.
The broader lesson is simple: users should never run commands copied from a website claiming to “verify” or “fix” access. That behavior turns social engineering into self-service malware installation, which is efficient only for criminals. DNS filtering, web protection, endpoint detection, script controls, and user awareness are all needed to stop these campaigns before a fake browser prompt becomes a remote-access foothold.
Introduction
Source: Unidentified RAT pushes NetSupport RAT, (Mon, Jun 1st) via SANS Internet Storm Center — published 01 Jun 2026.
Was this article helpful?
Your feedback helps us improve the knowledge base.