logo

New ClickFix Attack Uses Node.js Malware via Tor to Steal Crypto

ID: 2285a03e-8d38-5739-b565-66ffe5733893

STIX ID: report--2285a03e-8d38-5739-b565-66ffe5733893

Feed Name: HackRead

Threat Score
75/100

Date Published: 2026-04-08

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

**Executive summary:** Netskope Threat Labs describes the ClickFix campaign, a Malware-as-a-Service operation that lures victims with fake CAPTCHAs and uses a PowerShell downloader to install a Node.js-based RAT/infostealer (NodeServer-Setup-Full.msi) on Windows; the malware uses Tor, in-memory modules, fingerprinting to evade detection, persists as LogicOptimizer, and communicates with gRPC C2 (artifacts like support.proto/admin.proto) to enable affiliate-driven cryptocurrency theft.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.