AI Generated ClickFix Attack Delivers SmartRAT
ID: 020dd8d1-8b93-5515-ace5-70c81f3fceba
STIX ID: report--020dd8d1-8b93-5515-ace5-70c81f3fceba
Feed Name: Zscaler Security Research Blog
SmartRAT is a PowerShell-based banking RAT targeting Brazilian financial users that provides full remote access and credential/transaction theft via fake bank overlays, keylogging, QR-code interception/swap, screen streaming, file exfiltration, and remote command execution; it persists via scheduled tasks, registry Run keys, or an installed Windows service and communicates with C2 over AES-encrypted TCP (port 51888) using a domain (c.windowsupdate-cdn.com) with a hardcoded IP fallback (162.141.111.227). The report documents detailed TTPs, supported C2 commands and packets, local artifacts and paths, cryptographic operations (HMAC-SHA256 and AES-CBC), and critical operational weaknesses in the web-based C2 panel authentication.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
