logo

GrayAlpha Uses Diverse Infection Vectors to Deploy PowerNet Loader and NetSupport RAT

ID: cf0ccd75-0343-4b85-ab5f-b26fed6477af

STIX ID: report--cf0ccd75-0343-4b85-ab5f-b26fed6477af

Threat Score

78/100

Uploaded: 2026-08-14

Published Date: 2025-07-03

Last Modified Date: 2025-07-03

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
## Executive Summary Recorded Future details GrayAlpha (linked to FIN7) campaigns that use fake browser-update pages, fake 7-Zip download sites, and the TAG-124 traffic distribution system to deliver two custom PowerShell loaders (PowerNet and MaskBat) which ultimately deploy NetSupport RAT; the report includes infrastructure attribution, extensive IoCs (domains, IPs, MSIX certificate serials and hashes), and recommended mitigations such as application allow-listing and detection rules.