logo

Detecting an email-based ClickFix attack that delivers DCRat malware payload · Blog · Sublime Security

ID: 86f25cc8-61f2-599e-8436-42d1e1b60033

STIX ID: report--86f25cc8-61f2-599e-8436-42d1e1b60033

Feed Name: Sublime Security Blog

Threat Score
70/100

Date Published: 2026-01-09

Date Updated: 2026-05-01

...
...

This Attack Spotlight details a phishing campaign that impersonated Booking.com and used a fake CAPTCHA to copy an obfuscated PowerShell command into the victim's clipboard; when pasted and executed via Windows+R the command retrieves and runs DCRat (SHA256 08037de4a729634fa818ddf03ddd27c28c89f42158af5ede71cf0ae2d78fa198), saved as C:\Windows\Temp\tybd7.exe. The report outlines the full delivery chain, sample loader script, C2 domains, IOCs, and detection signals, and notes that Sublime's detection engine prevented the attack.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.