GrayCharlie is a threat actor active since 2023, known for compromising WordPress sites to distribute NetSupport RAT via fake browser updates.
Analyst brief
GrayCharlie is a threat actor active since 2023, primarily compromising WordPress sites to inject malicious JavaScript redirects. It targets organizations worldwide, with a particular focus on the US. The group employs two primary TTPs: fake browser update pages and ClickFix mechanisms to deliver the NetSupport RAT payload, using infrastructure linked to MivoCloud and HZ Hosting Ltd. for C2. Defenders should monitor for C2 servers associated with MivoCloud and HZ Hosting Ltd., suspicious WordPress redirects, and NetSupport RAT indicators.
GrayCharlie
unknown
GrayCharlie is a threat actor that compromises WordPress sites to inject malicious JavaScript, redirecting visitors to NetSupport RAT payloads via fake browser update pages or ClickFix mechanisms. Insikt Group has identified extensive infrastructure linked to GrayCharlie, primarily associated with MivoCloud and HZ Hosting Ltd., including command-and-control servers and staging infrastructure. The group employs two primary attack chains to deliver the NetSupport RAT, utilizing both fake updates and ClickFix techniques. GrayCharlie targets organizations worldwide, with a particular focus on the US, and has shown persistent behavior in its operations since its emergence in 2023.