Most Significant TTP 2026: NetSupport RAT Installation Following ClickFix-Style
Detects the deployment of NetSupport Manager (client32.exe) or related components when initiated by common scripting interpreters such as PowerShell, MSHTA, or CMD. This behavior is indicative of a ClickFix-style social engineering attack where a user is coerced into executing malicious commands to deploy remote access tools.
Sigma

