Top Tweets for #NetSupportRat
ISC Diary: #SmartApeSG campaign pushes #Remcos #RAT, #NetSupportRAT, #StealC and #SectopRAT (#ArechC https://t.co/g4XR3RCgxi

We started with #ClickFix putting #DonutLoader into memory and end with #NetSupportRAT
12 - #NetSupportRAT connects to it's C2 located in #Iran
172[.94[.9[.4
Hope this is helpful to the community!
7 of 7 (end of thread)

10 - Powershell inside MSI downloads a ZIP file from another website
hxxps://applicationhost17[.com/downloads/MS-D2DC127D-084C-44D1-8615-6142396987BB[.zip
11 - The ZIP contains #NetSupportRAT
https://t.co/iauGJwAD5C
6 of X

#ClickFix => #DonutLoader => #NetSupportRAT active right now 3/11/2026
step by step
1 - legit website loading malicious content
2 - shows ClickFix popup
3 - copy & paste powershell cmd & run it
... continued ...
1 of X (thread)

@smica83 All Samples are #NetSupportRat
Samples Collection with client32.ini
https://t.co/NETLTpLQAV

ac019d44897e15a643de5603d823f016
srvc-clndly[.]com
83[.]217[.]209[.]249
AS215826 Partner Hosting LTD 🇷🇺
#NetSupportRAT @smica83 @JAMESWT_WT
![skocherhan's tweet photo. ac019d44897e15a643de5603d823f016
srvc-clndly[.]com
83[.]217[.]209[.]249
AS215826 Partner Hosting LTD 🇷🇺
#NetSupportRAT @smica83 @JAMESWT_WT https://t.co/c2lAQ9Z8iy](https://pbs.twimg.com/media/HA3LyWWXMAANsPF.jpg)
mysrvcs[.]com
77[.]90[.]15[.]227
AS215365 Tom Gewiese 🇩🇪
37[.]77[.]150[.]202/fakeurl[.]htm
AS198953 Proton66 OOO 🇷🇺
👇
https://t.co/ql1vBMxcQJ
#NetSupportRAT @smica83 @JAMESWT_WT @abuse_ch
![skocherhan's tweet photo. mysrvcs[.]com
77[.]90[.]15[.]227
AS215365 Tom Gewiese 🇩🇪
37[.]77[.]150[.]202/fakeurl[.]htm
AS198953 Proton66 OOO 🇷🇺
👇
https://t.co/ql1vBMxcQJ
#NetSupportRAT @smica83 @JAMESWT_WT @abuse_ch https://t.co/mme65HV4R8](https://pbs.twimg.com/media/HAzuoFMWYAA1VTh.jpg)

#NetSupportRat
Client32.ini
MD5 9e4e8a03031260cc533ebeb2fca575b8
GatewayAddress=relativegoingplanning.]net:443
SecondaryGateway=185.39.19.]96:443
Reference
❇️https://t.co/8Z9wsUhVBk
Samples
✅https://t.co/6ezDuzrBMD
cc @500mk500
![JAMESWT_WT's tweet photo. #NetSupportRat
Client32.ini
MD5 9e4e8a03031260cc533ebeb2fca575b8
GatewayAddress=relativegoingplanning.]net:443
SecondaryGateway=185.39.19.]96:443
Reference
❇️https://t.co/8Z9wsUhVBk
Samples
✅https://t.co/6ezDuzrBMD
cc @500mk500 https://t.co/sJ7cvNjieW](https://pbs.twimg.com/media/G9cIrBuWIAAUuKD.jpg)
New JS#SMUGGLER malware campaign delivers #NetSupportRAT through compromised websites – hackers get full remote control of Windows machines.
Read: https://t.co/mx0KyZKOJz
#JSsmuggler #Malware #Cybersecurity #Windows
イラン系Bloody Wolfが中央アジアを標的にJavaドロッパー+Geo-fencingでNetSupport RATを展開。政府・防衛向け長期潜伏狙い。JAR実行制御とNetSupport監査が必須。#BloodyWolf #NetSupportRAT #APT https://t.co/LKlUQJ9pKw
restinoset[.]com
badylex[.]com
fetrhinospa[.]com
nebodune[.]com
menuderg[.]com
perropa[.]com
88[.]218[.]64[.]49/fakeurl[.]htm
AS209309 Oniks LLC 🇷🇺
#NetSupportRAT
![skocherhan's tweet photo. restinoset[.]com
badylex[.]com
fetrhinospa[.]com
nebodune[.]com
menuderg[.]com
perropa[.]com
88[.]218[.]64[.]49/fakeurl[.]htm
AS209309 Oniks LLC 🇷🇺
#NetSupportRAT https://t.co/ZGURmbsegX](https://pbs.twimg.com/media/G6VX7tyXIAETuM_.png)
Another "approve" related FUD on VT sample: 46ccbfc563eb008029e907807597295b6b4f813eeeebb078e31ff17839154a46
From: https://approveis[.]info/bVfrH7.png
82.118.16[.]207 - seen already, but still only 1 detection on VT...
🤷♂️
![malwrhunterteam's tweet photo. Another "approve" related FUD on VT sample: 46ccbfc563eb008029e907807597295b6b4f813eeeebb078e31ff17839154a46
From: https://approveis[.]info/bVfrH7.png
82.118.16[.]207 - seen already, but still only 1 detection on VT...
🤷♂️ https://t.co/hGQTD2rW0F](https://pbs.twimg.com/media/G6RYL6AXcAAU6-_.jpg)
新たなClickFix攻撃キャンペーン「EVALUSION」が判明。偽CAPTCHA誘導でユーザにコマンド貼付・実行させ、Amatera StealerとNetSupport RATを配布。クリップボード&クラウド経由手口。ユーザ教育と実行制御強化必須。#ClickFix #Amatera #NetSupportRAT
https://t.co/0JvD65Mm5j

#NetSupportRat
👇
5.181.156.]104:443
Client32.ini👇
47e7c3f9be83c57d7058e194fa411988
👇
https://t.co/emtPFmw76c
(Unverified) NetSupportRAT Found
C2: 118[.]174[.]71[.]22:7443
Country: Thailand (AS23969)
ASN: TOT-NET TOT Public Company Limited
#c2 #NetSupportRAT #unverified
(Unverified) NetSupportRAT Found
C2: 179[.]95[.]205[.]237:9990
Country: Brazil (AS18881)
ASN: TELEFONICA BRASIL S.A
#c2 #NetSupportRAT #unverified
(Unverified) NetSupportRAT Found
C2: 93[.]232[.]103[.]14:82
Country: Germany (AS3320)
ASN: DTAG Internet servic...
#c2 #NetSupportRAT #unverified
(Unverified) NetSupportRAT Found
C2: 51[.]34[.]39[.]107:51200
Country: Switzerland (AS16509)
ASN: AMAZON-02
#c2 #NetSupportRAT #unverified
🚨 New C2 Detected!
🔗 52[.]63[.]111[.]178
ℹ️ ASN: AS16509
ℹ️ ASN Organization: AMAZON-02
📍 Country: AU
📍 City: Sydney
📅 2025-09-07T16:02:00
ℹ️ Type: #cnc - #c2
ℹ️ Family: #NetSupportRAT
#ThreatIntelligence #IoCs #Malware
(Unverified) NetSupportRAT Found
C2: 79[.]241[.]108[.]185:81
Country: Germany (AS3320)
ASN: DTAG Internet servic...
#c2 #NetSupportRAT #unverified
Last Seen Hashtags on Sotwe
Most Popular Users

Elon Musk 
@elonmusk
240.2M followers

Barack Obama 
@barackobama
119.3M followers

Donald J. Trump 
@realdonaldtrump
111.6M followers

Cristiano Ronaldo 
@cristiano
109M followers

Narendra Modi 
@narendramodi
107M followers

Rihanna 
@rihanna
97.3M followers

NASA 
@nasa
92.1M followers

Justin Bieber 
@justinbieber
90.6M followers

KATY PERRY 
@katyperry
86.8M followers

Taylor Swift 
@taylorswift13
80.6M followers

Lady Gaga 
@ladygaga
72.2M followers

Kim Kardashian 
@kimkardashian
69.4M followers

YouTube 
@youtube
68.6M followers

Virat Kohli 
@imvkohli
68.6M followers

Bill Gates 
@billgates
63.4M followers

The Ellen Show
@theellenshow
62.5M followers

CNN 
@cnn
61.9M followers

Neymar Jr 
@neymarjr
61.1M followers

X 
@x
60.9M followers

Selena Gomez 
@selenagomez
59.9M followers





![skocherhan's tweet photo. mysrvcs[.]com
77[.]90[.]15[.]227
AS215365 Tom Gewiese 🇩🇪
37[.]77[.]150[.]202/fakeurl[.]htm
AS198953 Proton66 OOO 🇷🇺
👇
https://t.co/ql1vBMxcQJ
#NetSupportRAT @smica83 @JAMESWT_WT @abuse_ch https://t.co/mme65HV4R8](https://pbs.twimg.com/media/HAzuVcBaAAE3jSE.jpg)
![skocherhan's tweet photo. mysrvcs[.]com
77[.]90[.]15[.]227
AS215365 Tom Gewiese 🇩🇪
37[.]77[.]150[.]202/fakeurl[.]htm
AS198953 Proton66 OOO 🇷🇺
👇
https://t.co/ql1vBMxcQJ
#NetSupportRAT @smica83 @JAMESWT_WT @abuse_ch https://t.co/mme65HV4R8](https://pbs.twimg.com/media/HAztUk4aQAAklWT.jpg)
![skocherhan's tweet photo. mysrvcs[.]com
77[.]90[.]15[.]227
AS215365 Tom Gewiese 🇩🇪
37[.]77[.]150[.]202/fakeurl[.]htm
AS198953 Proton66 OOO 🇷🇺
👇
https://t.co/ql1vBMxcQJ
#NetSupportRAT @smica83 @JAMESWT_WT @abuse_ch https://t.co/mme65HV4R8](https://pbs.twimg.com/media/HAztDLabIAAEIoD.png)

![JAMESWT_WT's tweet photo. #NetSupportRat
Client32.ini
MD5 9e4e8a03031260cc533ebeb2fca575b8
GatewayAddress=relativegoingplanning.]net:443
SecondaryGateway=185.39.19.]96:443
Reference
❇️https://t.co/8Z9wsUhVBk
Samples
✅https://t.co/6ezDuzrBMD
cc @500mk500 https://t.co/sJ7cvNjieW](https://pbs.twimg.com/media/G9cH3QBW0AAeq5D.jpg)



![malwrhunterteam's tweet photo. Another "approve" related FUD on VT sample: 46ccbfc563eb008029e907807597295b6b4f813eeeebb078e31ff17839154a46
From: https://approveis[.]info/bVfrH7.png
82.118.16[.]207 - seen already, but still only 1 detection on VT...
🤷♂️ https://t.co/hGQTD2rW0F](https://pbs.twimg.com/media/G6RYKPjXYAAPSJo.jpg)
![malwrhunterteam's tweet photo. Another "approve" related FUD on VT sample: 46ccbfc563eb008029e907807597295b6b4f813eeeebb078e31ff17839154a46
From: https://approveis[.]info/bVfrH7.png
82.118.16[.]207 - seen already, but still only 1 detection on VT...
🤷♂️ https://t.co/hGQTD2rW0F](https://pbs.twimg.com/media/G6RYJEGXwAAzArf.jpg)

