GrayCharlie Deploys NetSupport via WordPress
GrayCharlie deploys NetSupport and other malicious software by injecting JavaScript into compromised WordPress sites. Since mid-2023, this threat actor has covertly embedded harmful scripts to facilitate malware delivery. Known for connections to the SmartApeSG cluster, GrayCharlie utilizes NetSupport RAT to gain control over infected systems and has expanded its arsenal to include Stealc and SectopRAT. By inserting script tags into the DOM, attackers redirect users to malicious JavaScript hosted on their servers. Visitors are tricked into executing or installing malware through deceptive browser updates or fake CAPTCHAs. Analysis reveals backend operations linked to MivoCloud and HZ Hosting Ltd. The intrusion strategy often targets legal firms, exploiting supply-chain vulnerabilities in IT service providers like SMB Team. To prevent breaches, security teams should monitor for unauthorized scripts, utilize detection rules, and block known malicious domains. For in-depth details on GrayCharlie’s tactics, visit the full article.
GrayCharlie Injects Malicious JavaScript into WordPress Sites to Deliver NetSupport RAT and Stealc
