logo

From ClickFix to MaaS: Exposing a Modular Windows RAT and Its Admin Panel

ID: 27e05b2a-5cc6-53ab-b5f8-49a3019ca39e

STIX ID: report--27e05b2a-5cc6-53ab-b5f8-49a3019ca39e

Feed Name: Netskope Threat Labs

Threat Score
78/100

Date Published: 2026-04-06

Date Updated: 2026-04-28

Author: Jan Michael Alcantara

...
...

Netskope Threat Labs documents an active ClickFix campaign delivering a modular Node.js infostealer/RAT via malicious MSI installers that bundle a Node runtime; the malware achieves persistence, decrypts a shuffled configuration to connect to a .onion gRPC C2 over Tor, loads stealing modules in-memory (avoiding disk artifacts), and is backed by a leaked admin.proto revealing a mature malware-as-a-service infrastructure focused on cryptocurrency wallet theft.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.