GrayCharlie Hacks WordPress Sites, Spreads NetSupport RAT and Stealc Malware
GrayCharlie is leveraging compromised WordPress sites to deploy malicious JavaScript scripts, facilitating the delivery of NetSupport RAT and potentially followed by Stealc and SectopRAT through deceptive browser updates and ClickFix tactics.
GrayCharlie is leveraging compromised WordPress sites to deploy malicious JavaScript scripts, facilitating the delivery of NetSupport RAT and potentially followed by Stealc and SectopRAT through deceptive browser updates and ClickFix tactics.
Insikt Group has identified GrayCharlie as a financially driven threat actor, overlapping with SmartApeSG, active since mid-2023. This entity specializes in transforming legitimate WordPress websites into platforms for malware distribution.
The threat actor embeds links to externally hosted JavaScript in compromised web pages, redirecting users to counterfeit browser-update pages or ClickFix-like social engineering processes, ultimately installing the NetSupport RAT.
Upon installation, NetSupport establishes a connection to attacker-controlled C2 servers, granting GrayCharlie operators remote access for surveillance, file manipulation, and subsequent payload delivery, including the Stealc infostealer and SectopRAT malware.
Insikt Group reports that GrayCharlie maintains an extensive and layered infrastructure, predominantly hosted by providers MivoCloud and HZ Hosting Ltd. This infrastructure includes dedicated NetSupport RAT C2 servers, servers hosting malicious JavaScript templates, and higher-tier systems for campaign management, often accessed via proxy services.
The operational techniques of GrayCharlie are consistent across campaigns, utilizing recurring infection chains, license keys, and TLS certificate patterns on its C2 infrastructure.
Insikt Group has identified GrayCharlie as a financially driven threat actor, overlapping with SmartApeSG, active since mid-2023.
Initially, GrayCharlie focused on fake browser update overlays, tailored to browsers like Chrome, Edge, or Firefox, misleading users into downloading a purported update package, which is a JavaScript-driven NetSupport installer.
The infrastructure's IP addresses are connected to websites impersonating "Wiser University," a fictitious entity demonstrating Wiser, a free Bootstrap HTML5 education template.
The loader script uses WScript to stage PowerShell, downloading and extracting the NetSupport client into directories such as %AppData%. It also adds Registry Run keys for persistence and communicates with GrayCharlie-controlled C2 servers.
In 2025, GrayCharlie expanded its approach to include a ClickFix flow, where compromised WordPress pages exhibit a fake CAPTCHA. This CAPTCHA copies a PowerShell-based command to the user's clipboard, instructing them to execute it via the Windows Run dialog, again leading to the installation and persistence of NetSupport RAT.
Victim sites appear to have been opportunistically compromised across various sectors. However, Insikt Group notes a significant cluster of US law firm WordPress sites beginning to load malicious JavaScript from GrayCharlie-controlled infrastructure around November 2025. Evidence indicates these law firm sites might have been compromised through a supply-chain vector involving a shared IT or marketing provider.
While GrayCharlie’s ultimate objectives are not entirely clear, current telemetry suggests aims of data theft, financial gain, and potentially selling or sharing access with other threat actors, highlighting the risk to legal and other high-value targets.
Insikt Group recommends aggressively blocking IP addresses and domains associated with NetSupport RAT, Stealc, SectopRAT, and other tools utilized in GrayCharlie operations. Traffic to known-compromised WordPress sites should be treated as high-risk until remediation is completed.
Security teams should deploy updated YARA, Snort, and Sigma rules to detect NetSupport components, ClickFix-style commands, and GrayCharlie’s JavaScript and PowerShell loader patterns, including in historical logs.
Additional recommended controls include tightening email and web filtering, monitoring for suspicious data exfiltration to known malicious infrastructure, and continuously updating GrayCharlie threat intelligence sources to keep detection and blocking policies current.
Based on reporting by GBHackers.
