New ClickFix Campaign Unveiled: Modular NodeJS Malware Targets Windows Users
ID: c8537fb7-ee83-5aca-99b2-731cb0fce8af
STIX ID: report--c8537fb7-ee83-5aca-99b2-731cb0fce8af
Feed Name: securityonline.info
Netskope Threat Labs describes a sophisticated ClickFix campaign that infects Windows users through a fake CAPTCHA which triggers a background PowerShell to download a self-contained MSI (NodeServer-Setup-Full.msi) bundling Node.js; the malware persists via registry, executes modular stealing modules in-memory (never writing core modules to disk), and communicates with a C2 over gRPC tunneled through Tor (using a local SOCKS5 proxy). The report highlights advanced evasion (AV fingerprinting), real-time operator infrastructure revealed by an accidentally leaked admin.proto, and MaaS-like features such as multi-operator role control, wallet tracking for cryptocurrency theft, and Telegram-based notifications.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
