Campaign record
NetSupport RAT via link-free mail
NetSupport RAT delivered by link-free emails posing as a software update
- Status as last assessed
- Active
- First seen
- 2024-09-05
- Last seen
- 2024-09-05
- Indicators
- 1
- Sources
- 1
- Targets
- Windows
- Fake software update notice
- NetSupport RAT
- Instruction-only email, no link or attachment
Original research
- Proofpoint2024-11-14Vendor researchFirst account
Security Brief: ClickFix Social Engineering Technique Floods Threat Landscape
This page summarises and structures that research; it is not a substitute for the original.
Researchers: if anything here misrepresents your work, email corrections@clickfixreport.com — we correct within 5 working days, no questions asked.
Summary
From 5 September 2024, Proofpoint saw mail signed "Security Agent" telling recipients that unnamed software on their machine had to be patched, with step-by-step wording for opening a terminal and typing an encoded command themselves. Nothing was attached and there was no link at all, which is why the message read as ordinary correspondence and had little for a mail gateway to catch. Running the command fetched a further script, which in turn pulled down 7-Zip together with a password-protected archive, unpacked it and started NetSupport, a legitimate remote-control product repurposed as a backdoor. Proofpoint notes that variants asking this much of the recipient are probably less productive than the ones that fill the clipboard for them. The sender address at a free German mail provider is the only indicator published for it.
Execution mechanisms
The only execution mechanism any published account describes for this campaign is PowerShell (T1059.001), which 19 of the 44 published campaigns in this corpus also record (43%).
Indicators
1 indicator, each present verbatim in at least one of the sources above. Values are shown defanged and are not links to the hosts — the link goes to our page for that indicator.
| Indicator | Type | Role | Assessment | First seen | Last seen | Report an error |
|---|---|---|---|---|---|---|
| email, shown defanged for safety: resizenreyl6 at web dot de | Other | Not yet assessed | 2024-09-05 | 2024-09-05 | Report an error in email record 37018ca6-bba5-4a14-810d-62a7ed82cfe5 |
“Assessment” is who controls the host, not how dangerous it is. Many of these are compromised legitimate sites whose owners are victims, and they are excluded from every blocklist file we publish.
Not on this record
This record does not yet carry a second publisher's account, any overlap with another campaign in this corpus or our own re-checks of these indicators. Each appears on this page as its own section once it exists; none of it is inferred.
Cite as
ClickFixReport, “NetSupport RAT via link-free mail”, campaign ID 6e742ac5, retrieved 2026-08-07, snapshot fb0eed7.
https://clickfixreport.com/campaigns/6e742ac5/netsupport-rat-fake-software-update-clickfix
Published under CC BY 4.0. Reuse it, including commercially, with attribution. The date above is when this record last changed, not when you opened it — the page is a versioned record, so that is the date a reader needs to find what you saw.