COVID-19 Phishing Email Drops NetSupport RAT

NJCCIC Alert

Original Release Date: 5/26/2020

Summary

COVID-19 phishing emails continue, this time installing a trojanized NetSupport Manager remote administration tool. Claiming to be from the Johns Hopkins Center, the email contains an attached document detailing the number of COVID-19 related deaths in the US. If macros are enabled, the NetSupport Manager client will be downloaded and installed from a remote site. NetSupport Manager is a legitimate tool used by administrators to gain remote access to client computers, though the tool has been weaponized by threat actors to serve as a remote access trojan (RAT). Once installed, the threat actor gains control of the device and is able to remotely execute commands. Additionally observed in this massive campaign, the NetSupport RAT further drops various malicious files, an obfuscated PowerSploit-based script, and connects to a command and control server, allowing the threat actor to send additional commands and enabling future attacks. Researchers assess that lateral movement within the network may be possible.

Recommendations

The NJCCIC recommends victims remove any infected devices from the network immediately upon discovery and scan other possible infected devices on the network. Additionally, we urge victims to change passwords once the device has been cleaned and enable multi-factor authentication where available. Additional information can be found in the Bleeping Computer article.

New Jersey Cybersecurity & Communications Integration Cell

2 Schwarzkopf Dr, Ewing Township, NJ 08628

njccic@cyber.nj.gov

OUR COMMITMENT

The NJCCIC is a component organization within the New Jersey Office of Homeland Security and Preparedness. We are the State's one-stop-shop for cyber threat analysis, incident reporting, and information sharing and are committed to making New Jersey more resilient to cyber threats by spreading awareness and promoting the adoption of best practices.

Agency Seals of State of NJ, NJOHSP and NJCCIC

STAY CONNECTED:

View our Privacy Policy here.

View our Site Index here.