ClickFix added nslookup commands to its arsenal for downloading RATs
ID: 0e92af21-adb2-5aac-94a0-87776ee12879
STIX ID: report--0e92af21-adb2-5aac-94a0-87776ee12879
Feed Name: Malwarebytes Blog
Malwarebytes describes a ClickFix campaign that uses social-engineering lures (fake CAPTCHAs, fake updates, crash prompts, tutorial videos) to trick users into copy-pasting and executing nslookup commands. Attackers abuse nslookup replies to smuggle commands and pointers to a ZIP archive; the archive contains a malicious Python script that performs discovery and drops a VBScript which installs ModeloRAT, providing remote access to infected Windows machines. The report advises users to avoid running untrusted commands, type rather than paste commands, keep anti-malware up-to-date, and be cautious of urgency-based prompts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
