Hackers Use ClickFix Lure to Drop Node.js-Based Windows RAT With Tor-Powered C2
ID: 72d64c12-3815-5d8e-ad3f-0a5357f5326d
STIX ID: report--72d64c12-3815-5d8e-ad3f-0a5357f5326d
Feed Name: cybersecurityNews.com
A ClickFix social-engineering campaign tricks Windows users into running a base64 PowerShell command that silently installs a Node.js-based RAT (NodeServer-Setup-Full.msi) which extracts to %LOCALAPPDATA%\LogicOptimizer\, registers persistence via the Registry Run key, and launches Node.js via conhost.exe; the modular malware retrieves theft modules in memory from a Tor .onion C2 (using the Tor Expert Bundle and gRPC), is offered as Malware-as-a-Service with an exposed admin panel, and operators should monitor for unexpected Node.js/conhost.exe processes, Tor traffic, and new Registry Run entries.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
