ClickFix added nslookup commands to its arsenal for downloading RATs
ID: 9a31fac7-a305-5015-8b15-ee7ea99c3c89
STIX ID: report--9a31fac7-a305-5015-8b15-ee7ea99c3c89
Feed Name: Security Boulevard
The report describes ongoing ClickFix campaigns that trick users into executing malicious copy‑paste commands, now abusing nslookup to fetch a ZIP that extracts a Python script, stages a VBScript, and ultimately deploys ModeloRAT for remote control of Windows systems. It outlines the social-engineering lures (fake CAPTCHAs, updates, browser crashes, tutorial videos), the evasion of blocked mshta/PowerShell via nslookup-based payload delivery, and provides high-level defense guidance (avoid untrusted commands, slow down, minimize copy-paste, use real-time protection, and stay informed).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
