BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

New JS#SMUGGLER Campaign Distributes NetSupport RAT Malware

Advanced Multi-Stage Malware Campaigns JS#SMUGGLER and CHAMELEON#NET Employ Stealthy Delivery and Evasion Techniques to Distribute NetSupport RAT and Formbook Malware

  • A new cyber campaign called JS#SMUGGLER uses compromised websites to distribute NetSupport RAT, a remote access trojan.
  • The attack involves obfuscated JavaScript loaders, HTML Applications (HTA), and PowerShell payloads to execute Malware stealthily.
  • Device-aware delivery methods customize infection routes based on whether the victim uses a mobile or desktop device.
  • Another campaign, CHAMELEON#NET, spreads Formbook malware through phishing emails targeting social security sector users.
  • Both campaigns employ complex multi-stage loaders and evasion techniques to avoid detection and maintain persistence.

Cybersecurity researchers have identified a new malware campaign called JS#SMUGGLER that spreads the remote access trojan NetSupport RAT via compromised websites. The campaign uses several steps: embedding obfuscated JavaScript loaders into websites, deploying HTML Application (HTA) files executed with “mshta.exe,” and running encrypted PowerShell scripts that download and activate the main malware. These attacks have targeted enterprise users broadly but have not been attributed to any known threat actor or country.

- Advertisement -

This multi-stage attack employs hidden iframes and obfuscated scripts to mask its activity. The JavaScript loader, named “phone.js,” is downloaded silently and profiles the visitor’s device to decide between showing a full-screen iframe on mobile or loading a second-stage script on desktops. The loader also uses tracking to activate the malicious payload only once per visit, reducing the chance of detection. The invisible iframe redirects victims to malicious URLs, leading to the download and execution of an HTA payload. This payload runs a PowerShell stager in memory after decrypting it, deletes itself afterward, and helps deliver NetSupport RAT, which allows attackers to control victim machines remotely. According to Securonix, the use of layered evasion techniques suggests a professional malware operation and recommends measures like script monitoring and PowerShell logging to defend against this threat (source).

Weeks earlier, Securonix reported another multi-stage malware campaign named CHAMELEON#NET, which distributes Formbook malware—a keylogger and data stealer—through phishing emails. This campaign targets individuals in the social security sector, using fake webmail portals to trick victims into downloading a .BZ2 archive. The archive initiates a complex infection involving a heavily obfuscated JavaScript dropper that writes additional scripts and executable loaders to disk. A .NET loader decrypts and executes Formbook entirely in memory using reflection and a custom XOR cipher to avoid detection. Persistence is maintained by adding the malware to startup folders or modifying the Windows Registry (source).

Both campaigns demonstrate the use of sophisticated multi-layered attack chains, combining social engineering, obfuscation, and fileless execution techniques to compromise targeted systems and maintain stealth.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

- Advertisement -

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

CFTC Sues New York to Block State Gambling Laws on Markets

The CFTC has sued New York to prevent state gambling laws from being applied...

Bitcoin Eyes May Rally as Fed Holds Rates Steady

Bitcoin gained over 13% in April and held above $77,000, signaling strong momentum heading...

Brazil Shuts 27 Prediction Markets, Citing Debt Risk

Brazilian regulators ordered the shutdown of 27 prediction market platforms, including Kalshi and Polymarket,...

CISA Adds 4 Exploited Flaws to KEV Catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added four actively exploited vulnerabilities to...

Palantir CEO Sees AI Agents Driving Bitcoin Adoption

Palantir co-founder Joe Lonsdale states AI agents could become a major driver for Bitcoin...

Must Read

Best Crypto Audiobooks of 2026: The Ultimate Listen & Learn Guide

You can't read Bitcoin charts while driving 70 mph on the highway. You can't study Ethereum whitepapers during your morning run. But you can...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading