Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors GrayCharlie

Also known as: ArechClient2, tracked as, Nitroade Hauler, ZPHP, HANEYMANEY, LandUpdate808, BlackCat, Gookee, kapuchin0, Guki, leaked the source code, shut the operation down, Kongtuke, Royal Ransomware

Description

GrayCharlie first emerged in mid‑2023 and has since built a sophisticated web‑based delivery chain that hinges on compromising popular content management systems – notably WordPress. Infected sites host injected external JavaScript that profiles visitors, displays fake browser update dialogs or ClickFix‑style pop‑ups, and then redirects users to download the NetSupport RAT. Once remote access is established, the actor plants auxiliary infostealers such as Stealc and SectopRAT to harvest credentials and sensitive data. The operation relies heavily on cloud hosting platforms – most prominently MivoCloud and HZ Hosting – which provide shared‑resource staging environments. Two distinct command‑and‑control clusters have been identified, separated by TLS certificate identity and license key patterns used by NetSupport. The infrastructure also incorporates traffic distribution systems (TDS) to evade detection. GrayCharlie’s supply‑chain tactics are evident in recent U.S. law‑firm campaigns, where compromised third‑party vendors appear to serve as footholds for the infection chain.

Goals & Targeting

Targeted Sectors

Financial services
Legal services
Government
Healthcare
Defense
Education
Telecommunications
Critical infrastructure
Manufacturing
Media
Retail
Gaming
Non profit
Information technology
Hospitality
Aerospace
Maritime
Nuclear
Entertainment
Food agriculture
Construction
Transportation

Targeted Countries / Regions

US
CN
RU
IN
UA
GB
DE
KP
IR
PK
BY
PL
TW
CA
AU
JP

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 1 day ago

Executive Summary

GrayCharlie is a financially motivated threat actor that compromised WordPress sites to serve malicious JavaScript, delivering NetSupport RAT via fake browser update pages or ClickFix pop‑ups. The group also drops infostealers such as Stealc and SectopRAT and leverages shared hosting infrastructure for staging and command‑and‑control. CISO briefing: The actor targets a wide geographic and sector range, with recent activity focused on U.S. law firms through compromised WordPress backends.

Goals & Targeting

The actor seeks financial gain primarily through ransomware or monetized data exfiltration; its extensive use of infostealers suggests a dual strategy of immediate credential theft and later leverage for larger payouts. Target selection spans high‑profile sectors—finance, legal, government—and a global footprint, with the U.S., UK, Australia, Canada, Japan, China, Ukraine, Russia, India, and Central Asian states among its focus. The group appears opportunistic but methodical: it exploits popular CMS platforms to maximize outreach, then uses layered payloads to expand lateral movement before monetization.

Enhanced Description

Key Capabilities

  • Inject malicious JavaScript into WordPress sites
  • Serve fake browser update pages via injected scripts
  • Deploy NetSupport RAT upon redirect
  • Drop Stealc and SectopRAT infostealers after infection
  • Profile visitors through injected code
  • Maintain staging infrastructure on shared hosts (MivoCloud, HZ Hosting)
  • Use traffic distribution systems to evade detection

MITRE ATT&CK Tactics

Initial Access
Execution
Command and Control
Persistence
Exfiltration
Impact

ATT&CK Techniques

T1071.001
T1105
T1133
T1189
T1204
T1190
T1567
T1657
T1048
T1486

Software / Tooling

NetSupport RAT
Stealc
SectopRAT

Campaigns & Victims

GrayCharlie has demonstrated a consistent, low‑profile operation cycle that exploits publicly accessible web applications to embed malicious delivery scripts. Infections are typically staged on shared hosting platforms, allowing rapid deployment across multiple victim sites before detection. The actor’s most recent notable operation targeted U.S. law firms in late 2025, likely leveraging a compromised shared IT provider as an entry point. Operational tempo appears steady but adaptive: the group updates its TLS certificates and license key mechanisms to avoid long‑term tracking while scaling its command‑and‑control infrastructure across separate clusters. Victim types cover a broad spectrum—financial services, legal firms, healthcare institutions—reflecting a strategy of capturing high‑value data with an eye toward future ransom or espionage exploitation.

IOC Patterns

  • Domain or subdomain references (e.g., persistancejs.store)
  • IP addresses tied to command-and-control servers
  • TLS certificate serial number and license key patterns for NetSupport RAT
  • JavaScript file URLs used in malicious redirects
  • Patterns of JavaScript injection on WordPress sites
  • Fake update prompts resembling ClickFix
  • Traffic distribution system identifiers

Recommended Actions

  • Block threat actor IP addresses and domains associated with RATs and infostealers Flag or block HTTP requests to compromised websites identified in the IOC list Deploy YARA, Snort, and Sigma detection rules for known malicious scripts and download patterns Implement email filtering and sandboxing to mitigate phishing via fake update prompts or ClickFix-style pop-ups Monitor outbound traffic for exfiltration over web services or alternative protocols

Suggested Tags

GrayCharlie
WordPress
Fake Browser Update
ClickFix
NetSupport RAT
Stealc
SectopRAT
Remote Access Trojan
Infostealer
Web-based Delivery
US Law Firm Targeting
MivoCloud
HZ Hosting
Supply Chain Compromise
Financial Theft
Exfiltration over Web Service

Confidence Assessment

The available data indicates clear evidence of WordPress-based delivery and use of NetSupport RAT, Stealc, and SectopRAT. However, uncertainties remain regarding the actor’s origin, complete motivation spectrum beyond finance, and precise command‑and‑control architecture due to limited publicly documented infrastructure fingerprints. Further investigation into associated TLS certificate attributes and additional hosting platforms would help close these gaps. Sources

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. www.recordedfuture.com — Cited by web research for: ZPHP
  2. unit42.paloaltonetworks.com — Cited by web research for: BlackCat
  3. research.checkpoint.com — Cited by web research for: RoundCube
  4. malpedia.caad.fkie.fraunhofer.de — Cited by web research for: curl
  5. hxxps://persistancejs.store/work/original.js — Cited by AI analysis.

Intel Summary

10

Techniques

41

Tools

0

Campaigns

40

IOCs

0

Observed Data

6

Tactics

Tags

Backdoor / C2
APT
Malware Distribution
Web Application Attacks
Global Threat Actor
GrayCharlie
WordPress
Fake Browser Update
ClickFix
NetSupport RAT
Stealc
SectopRAT
Remote Access Trojan
Infostealer
Web-based Delivery
US Law Firm Targeting
MivoCloud
HZ Hosting
Supply Chain Compromise
Financial Theft
Exfiltration over Web Service

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
China (CN)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.