Alerts
Events
DCR
Explore Cyware Products
Alerts
Events
DCR
Go to listing page
GrayAlpha Unmasked: New FIN7-Linked Infrastructure, PowerNet Loader, and Fake Update Attacks
Threat Actors
June 14, 2025
recordedfuture
GrayAlpha, a threat actor overlapping with FIN7, has been observed deploying NetSupport RAT using diverse infection vectors and custom loaders. The group utilizes PowerNet, a PowerShell loader, and MaskBat.
Read More
GrayAlpha
FIN7
NetSupport RAT
PowerNet
MaskBat
Publisher
Previous
Government offices in North Carolina, Georgia disrupted ...
Breaches and Incidents
Next
Medical software maker Episource data breach leaks thou ...
Breaches and Incidents