logo

ClickFix Attacks Abuses DNS Lookup Command to Deliver ModeloRAT

ID: f648d74d-dbc7-5e1d-a26d-32a23d3d7a43

STIX ID: report--f648d74d-dbc7-5e1d-a26d-32a23d3d7a43

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2026-02-17

Date Updated: 2026-04-21

Author: Elizabeth Montalbano

...
...

ClickFix attacks have evolved to abuse nslookup/DNS lookups as a new evasion technique to smuggle instructions and download a ZIP that drops a Python-based RAT (ModeloRAT), with attackers relying on fake CAPTCHA and social engineering to get victims to paste commands that self-infect their devices. Microsoft and Malwarebytes observed this shift away from blocked PowerShell/mshta techniques; the report details the delivery chain, enterprise impact potential, and advises users to avoid running commands from untrusted sources, verify instructions, and refrain from copy-pasting commands.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.