NetSupport RAT Exploited in Horns&Hooves Cyberattack

Red | Attack Report
Download PDF

The Horns&Hooves campaign, active since March 2023, targets Russian users by delivering malware disguised as legitimate business documents. Utilizing malicious JScript files, attackers aim to install the NetSupport RAT (Remote Access Trojan) on victims’ systems. The campaign has evolved from HTA scripts to more sophisticated obfuscated JavaScript files to evade detection. Connections to other cybercriminal groups, particularly TA569, highlight the collaborative nature of these threats and the need for ongoing vigilance in cybersecurity.

What’s new on HivePro

Get through updates and upcoming events, and more directly in your inbox