Tag
high
advisory
ClickFix 'BackgroundFix' Campaign Delivers CastleLoader, NetSupport RAT, and CastleStealer
2 rules 3 TTPs 1 IOCThe 'BackgroundFix' ClickFix campaign uses social engineering to trick victims into downloading malware disguised as a free image-editing tool, leading to the deployment of CastleLoader, NetSupport RAT for remote access, and CastleStealer for credential theft.
Microsoft Windows +2
clickfix
malware
social-engineering
rat
infostealer
castleloader
netsupport
2r
3t
1i
high
advisory
NetSupport Manager Execution from Unusual Path
2 rules 1 TTPThis rule detects the execution of NetSupport remote access software from non-default paths, potentially indicating an adversary abusing NetSupport Manager for malicious remote control.
NetSupport Manager
command_and_control
remote_access_tool
netsupport
2r
1t