From ClickFix to MaaS: Exposing a Modular Windows RAT and Its Admin Panel
ID: 27e05b2a-5cc6-53ab-b5f8-49a3019ca39e
STIX ID: report--27e05b2a-5cc6-53ab-b5f8-49a3019ca39e
Feed Name: Netskope Threat Labs
Threat Score
Netskope Threat Labs documents an active ClickFix campaign delivering a modular Node.js infostealer/RAT via malicious MSI installers that bundle a Node runtime; the malware achieves persistence, decrypts a shuffled configuration to connect to a .onion gRPC C2 over Tor, loads stealing modules in-memory (avoiding disk artifacts), and is backed by a leaked admin.proto revealing a mature malware-as-a-service infrastructure focused on cryptocurrency wallet theft.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
