Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

GrayCharlie Hacks WordPress Sites, Spreads NetSupport RAT and Stealc Malware

GrayCharlie is leveraging compromised WordPress sites to deploy malicious JavaScript scripts, facilitating the delivery of NetSupport RAT and potentially followed by Stealc and SectopRAT through deceptive browser updates and ClickFix tactics.

GrayCharlie is leveraging compromised WordPress sites to deploy malicious JavaScript scripts, facilitating the delivery of NetSupport RAT and potentially followed by Stealc and SectopRAT through deceptive browser updates and ClickFix tactics.

Insikt Group has identified GrayCharlie as a financially driven threat actor, overlapping with SmartApeSG, active since mid-2023. This entity specializes in transforming legitimate WordPress websites into platforms for malware distribution.

The threat actor embeds links to externally hosted JavaScript in compromised web pages, redirecting users to counterfeit browser-update pages or ClickFix-like social engineering processes, ultimately installing the NetSupport RAT.

Upon installation, NetSupport establishes a connection to attacker-controlled C2 servers, granting GrayCharlie operators remote access for surveillance, file manipulation, and subsequent payload delivery, including the Stealc infostealer and SectopRAT malware.

Insikt Group reports that GrayCharlie maintains an extensive and layered infrastructure, predominantly hosted by providers MivoCloud and HZ Hosting Ltd. This infrastructure includes dedicated NetSupport RAT C2 servers, servers hosting malicious JavaScript templates, and higher-tier systems for campaign management, often accessed via proxy services.

The operational techniques of GrayCharlie are consistent across campaigns, utilizing recurring infection chains, license keys, and TLS certificate patterns on its C2 infrastructure.

Insikt Group has identified GrayCharlie as a financially driven threat actor, overlapping with SmartApeSG, active since mid-2023.
Noah Redmond · Thehackingpost

Initially, GrayCharlie focused on fake browser update overlays, tailored to browsers like Chrome, Edge, or Firefox, misleading users into downloading a purported update package, which is a JavaScript-driven NetSupport installer.

The infrastructure's IP addresses are connected to websites impersonating "Wiser University," a fictitious entity demonstrating Wiser, a free Bootstrap HTML5 education template.

The loader script uses WScript to stage PowerShell, downloading and extracting the NetSupport client into directories such as %AppData%. It also adds Registry Run keys for persistence and communicates with GrayCharlie-controlled C2 servers.

In 2025, GrayCharlie expanded its approach to include a ClickFix flow, where compromised WordPress pages exhibit a fake CAPTCHA. This CAPTCHA copies a PowerShell-based command to the user's clipboard, instructing them to execute it via the Windows Run dialog, again leading to the installation and persistence of NetSupport RAT.

Victim sites appear to have been opportunistically compromised across various sectors. However, Insikt Group notes a significant cluster of US law firm WordPress sites beginning to load malicious JavaScript from GrayCharlie-controlled infrastructure around November 2025. Evidence indicates these law firm sites might have been compromised through a supply-chain vector involving a shared IT or marketing provider.

Advertisement

While GrayCharlie’s ultimate objectives are not entirely clear, current telemetry suggests aims of data theft, financial gain, and potentially selling or sharing access with other threat actors, highlighting the risk to legal and other high-value targets.

Insikt Group recommends aggressively blocking IP addresses and domains associated with NetSupport RAT, Stealc, SectopRAT, and other tools utilized in GrayCharlie operations. Traffic to known-compromised WordPress sites should be treated as high-risk until remediation is completed.

Security teams should deploy updated YARA, Snort, and Sigma rules to detect NetSupport components, ClickFix-style commands, and GrayCharlie’s JavaScript and PowerShell loader patterns, including in historical logs.

Additional recommended controls include tightening email and web filtering, monitoring for suspicious data exfiltration to known malicious infrastructure, and continuously updating GrayCharlie threat intelligence sources to keep detection and blocking policies current.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories