Suspicious NetSupport Manager Remote Client Execution From User-Writable Path

PremiumReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-10-09
Updated
2026-10-09

ATT&CK techniques

C2
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. Exfiltration

  13. Impact

What it detects

This rule detects the NetSupport Manager remote control client client32.exe launching from a user AppData or Temp directory instead of a standard installation path. The Stan Ghouls intrusions weaponized NetSupport RAT by dropping client32.exe alongside PCICHEK.DLL into user-writable folders as reported by Kaspersky. Running this legitimate remote access tool from the wrong location indicates unauthorized remote control rather than sanctioned IT usage.

Related detections9 linkedT1219 — drag to rearrange
Suspicious PowerShell Enabling OpenSSH Server With Attacker Keys via process_creation
Suspicious Curl Download to Update Executable during FortiClient EMS Exploitation
Suspicious MeshAgent Masquerading as NetworkDrivers Spawned by PowerShell
Malicious MeshCentral Agent Installation With Campaign Naming
Suspicious SimpleHelp Remote Access Tool Dropped In ProgramData Root
Suspicious MeshAgent Installation Arguments (via process_creation)
Possible AnyDesk Execution from Non-Standard Directory (via process_creation)
Suspicious MeshAgent Spawning Command Interpreter (via process_creation)
Suspicious AnyDesk Execution from Temporary or System Directory (via process_creation)
Suspicious NetSupport Manager Remote Client Execution From User-Writable Path
Pivot detection · T1219 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.