Also known as: ArechClient2, tracked as, Nitroade Hauler, ZPHP, HANEYMANEY, LandUpdate808, BlackCat, Gookee, kapuchin0, Guki, leaked the source code, shut the operation down, Kongtuke, Royal Ransomware
GrayCharlie first emerged in mid‑2023 and has since built a sophisticated web‑based delivery chain that hinges on compromising popular content management systems – notably WordPress. Infected sites host injected external JavaScript that profiles visitors, displays fake browser update dialogs or ClickFix‑style pop‑ups, and then redirects users to download the NetSupport RAT. Once remote access is established, the actor plants auxiliary infostealers such as Stealc and SectopRAT to harvest credentials and sensitive data. The operation relies heavily on cloud hosting platforms – most prominently MivoCloud and HZ Hosting – which provide shared‑resource staging environments. Two distinct command‑and‑control clusters have been identified, separated by TLS certificate identity and license key patterns used by NetSupport. The infrastructure also incorporates traffic distribution systems (TDS) to evade detection. GrayCharlie’s supply‑chain tactics are evident in recent U.S. law‑firm campaigns, where compromised third‑party vendors appear to serve as footholds for the infection chain.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
GrayCharlie is a financially motivated threat actor that compromised WordPress sites to serve malicious JavaScript, delivering NetSupport RAT via fake browser update pages or ClickFix pop‑ups. The group also drops infostealers such as Stealc and SectopRAT and leverages shared hosting infrastructure for staging and command‑and‑control. CISO briefing: The actor targets a wide geographic and sector range, with recent activity focused on U.S. law firms through compromised WordPress backends.
Goals & Targeting
The actor seeks financial gain primarily through ransomware or monetized data exfiltration; its extensive use of infostealers suggests a dual strategy of immediate credential theft and later leverage for larger payouts. Target selection spans high‑profile sectors—finance, legal, government—and a global footprint, with the U.S., UK, Australia, Canada, Japan, China, Ukraine, Russia, India, and Central Asian states among its focus. The group appears opportunistic but methodical: it exploits popular CMS platforms to maximize outreach, then uses layered payloads to expand lateral movement before monetization.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
GrayCharlie has demonstrated a consistent, low‑profile operation cycle that exploits publicly accessible web applications to embed malicious delivery scripts. Infections are typically staged on shared hosting platforms, allowing rapid deployment across multiple victim sites before detection. The actor’s most recent notable operation targeted U.S. law firms in late 2025, likely leveraging a compromised shared IT provider as an entry point. Operational tempo appears steady but adaptive: the group updates its TLS certificates and license key mechanisms to avoid long‑term tracking while scaling its command‑and‑control infrastructure across separate clusters. Victim types cover a broad spectrum—financial services, legal firms, healthcare institutions—reflecting a strategy of capturing high‑value data with an eye toward future ransom or espionage exploitation.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The available data indicates clear evidence of WordPress-based delivery and use of NetSupport RAT, Stealc, and SectopRAT. However, uncertainties remain regarding the actor’s origin, complete motivation spectrum beyond finance, and precise command‑and‑control architecture due to limited publicly documented infrastructure fingerprints. Further investigation into associated TLS certificate attributes and additional hosting platforms would help close these gaps. Sources
No campaigns linked yet.
No observed data linked yet.
10
Techniques
41
Tools
0
Campaigns
40
IOCs
0
Observed Data
6
Tactics