New ClickFix Attack Uses Node.js Malware via Tor to Steal Crypto
ID: 2285a03e-8d38-5739-b565-66ffe5733893
STIX ID: report--2285a03e-8d38-5739-b565-66ffe5733893
Feed Name: HackRead
Threat Score
**Executive summary:** Netskope Threat Labs describes the ClickFix campaign, a Malware-as-a-Service operation that lures victims with fake CAPTCHAs and uses a PowerShell downloader to install a Node.js-based RAT/infostealer (NodeServer-Setup-Full.msi) on Windows; the malware uses Tor, in-memory modules, fingerprinting to evade detection, persists as LogicOptimizer, and communicates with gRPC C2 (artifacts like support.proto/admin.proto) to enable affiliate-driven cryptocurrency theft.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
