Skip to main content
NetSupport RAT: Phishing ZIP to Domain Compromise operation cover
COMING SOONIntermediatePRO

NetSupport RAT: Phishing ZIP to Domain Compromise

A finance coordinator opened a ZIP that posed as an overdue invoice. Inside was an obfuscated JavaScript dropper that spawned PowerShell, downloaded a NetSupport Manager remote-control client, and ran it as a RAT from AppData. The operator enumerated the domain, reused a domain admin credential to RDP into the domain controller, dumped the NTDS.dit database, and tunneled it out. Trace the kill chain from the phishing email to full domain compromise.

1h
8 tasks
50 points
Pro

Launches in 5 days

Oct 13, 2026

Tuesday, October 13, 2026 at 9:00 AM

View Pro plans

Pro unlocks this operation at launch.

Training Tools

SIEMEmailXDRFirewallQuery

What you'll investigate

8 objectives unlock when this operation goes live.

1Scope the intrusion
2Identify the phishing sender
3Trace the script execution
4Recover the delivery host
5Pin the command-and-control gateway
6Identify the credential dumped from the domain controller
7Find the exfiltration endpoint
8Classify the remote-access tradecraft

Be first when it launches

Create your account and grab Pro before launch. The moment this operation goes live on Oct 13, 2026, you can jump straight in.

Get Started Free