Phishing Series 2026: NetSupport RAT Client Execution from Non-Standard Install Path

Detects the execution of NetSupport Remote Access Tool (RAT) components (client32.exe, Nskbfltr.sys, or TCCTL32.dll) from locations outside of the standard program installation directories. This behavior is often indicative of unauthorized persistence or masquerading by malware utilizing remote support software for C2.