Tor-Backed ClickFix Campaign Drops Node.js RAT on Windows
ID: 49473338-e89c-5f8c-a645-ce58bb4df4ca
STIX ID: report--49473338-e89c-5f8c-a645-ce58bb4df4ca
Feed Name: GBHackers
Netskope Threat Labs documents an active ClickFix campaign where victims are tricked by fake CAPTCHA pages into running a Base64-encoded PowerShell command that silently installs a NodeServer-Setup-Full.msi bundling a Node.js runtime; the installed malware executes JavaScript modules in memory, establishes Tor-backed gRPC communications to a C2, profiles targets (including AV checks and geo/IP), persists via the Run registry, and is linked to a larger malware-as-a-service ecosystem after an OPSEC leak exposed backend protocol files and multi-operator features.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
