NetSupport RAT Exploited in Horns&Hooves Cyberattack

Red | Attack Report
Download PDF

The Horns&Hooves campaign, active since March 2023, targets Russian users by delivering malware disguised as legitimate business documents. Utilizing malicious JScript files, attackers aim to install the NetSupport RAT (Remote Access Trojan) on victims’ systems. The campaign has evolved from HTA scripts to more sophisticated obfuscated JavaScript files to evade detection. Connections to other cybercriminal groups, particularly TA569, highlight the collaborative nature of these threats and the need for ongoing vigilance in cybersecurity.

What’s new on HivePro

Get through updates and upcoming events, and more directly in your inbox

Cyber Horizons 2025

What Last Year’s Attacks Reveal About Today’s Risks

Watch the Webinar on-demand and get a FREE copy of our Cyber Horizons 2025 report.

Our Speakers
Speaker 1

Prateek Bhajanka Global Field CISO & Former Gartner Analyst Hive Pro Inc.

Speaker 2

Ankit Mani Manager Threat Intel HiveForce Labs

Speaker 3

Sreevani Tonipe Senior Threat Researcher HiveForce Labs