Unidentified RAT pushes NetSupport RAT, (Mon, Jun 1st)

2026-06-01T01:23:48Z1a128d8e1c0e0379aa68120e0308fff3383cafdc59653f9190d88d51f8214f65
akiracredential-theftdshieldforensicsmalwaremicrosoft-accessnetsupportpodcastransomwareratrsssans-iscstealertelemetrythreat-intelvbayarayara-x

What happened

SANS ISC diary RSS feed (items dated May 25–Jun 1, 2026) summarizing multiple posts: an Unidentified RAT observed pushing NetSupport RAT; YARA‑X 1.17.0 release (performance improvements and a bugfix); analysis of a year of files uploaded to DShield sensors (telemetry/Kibana); an Akira ransomware kill‑chain reconstruction focused on pre‑impact perimeter and Windows event logs; a possible ACR stealer page impersonating Claude; a note on Microsoft Access VBA containing code; and several ISC Stormcast podcast entries. Topics cover malware/RAT activity, credential/stealer threats, ransomware forenS

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
1a128d8e1c0e0379aa68120e0308fff3383cafdc59653f9190d88d51f8214f65
Enrichment time
2026-06-01T01:23:48Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Unidentified RAT pushes NetSupport RAT, (Mon, Jun 1st) · Baitaphish