logo

Tor-Backed ClickFix Campaign Drops Node.js RAT on Windows

ID: 49473338-e89c-5f8c-a645-ce58bb4df4ca

STIX ID: report--49473338-e89c-5f8c-a645-ce58bb4df4ca

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-04-07

Date Updated: 2026-07-21

Author: Mayura Kathir

...
...

Netskope Threat Labs documents an active ClickFix campaign where victims are tricked by fake CAPTCHA pages into running a Base64-encoded PowerShell command that silently installs a NodeServer-Setup-Full.msi bundling a Node.js runtime; the installed malware executes JavaScript modules in memory, establishes Tor-backed gRPC communications to a C2, profiles targets (including AV checks and geo/IP), persists via the Run registry, and is linked to a larger malware-as-a-service ecosystem after an OPSEC leak exposed backend protocol files and multi-operator features.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.