• CommunityEnterprisePlans
  • Intel Exchange
    Intel ExchangeDetections
  • Resources
  • About
  • Leaderboard
Join CommunitySign In
    All Detections

    NetSupport Manager (client32.exe) RAT execution on Windows host

    avatar
    GlassDiceBearhttps://www.dicebear.comhttps://creativecommons.org/publicdomain/zero/1.0/„Glass” (https://www.dicebear.com) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)
    Ibrahim Saud@tektrix
    •updated 23 days ago•0•0•2

    Detects the execution of NetSupport Manager's 'client32.exe' process. This remote administration tool is frequently abused by threat actors for unauthorized persistence and remote control after being delivered via malicious payloads such as Google Apps Scripts in phishing campaigns.

    YARA-L

    Tags

    T1219 - Remote Access ToolsProcess CreationWindows

    Found in

    • Google Doc Sidebar Delivers Cross-Platform Stealer MalwareLast updated 23 days ago
    • Google Doc Sidebar Delivers Cross-Platform Stealer MalwareLast updated 23 days ago
    • Google Doc Sidebar Delivers Cross-Platform Stealer MalwareLast updated 23 days ago
    • Google Doc Sidebar Delivers Cross-Platform Stealer MalwareLast updated 23 days ago
    • Google Doc Sidebar Delivers Cross-Platform Stealer MalwareLast updated 23 days ago

    Community Inspired.
    AI Enhanced.
    Better Detections.

    Follow Us

    Company

    • About
    • Leaderboard

    Product

    • Community
    • Enterprise
    • Plans

    © 2026 Copyright. All Rights Reserved.

    Privacy PolicyTerms of Service

    Sign up to view this detection

    or

    Already have an account?