logo

ClickFix added nslookup commands to its arsenal for downloading RATs

ID: 9a31fac7-a305-5015-8b15-ee7ea99c3c89

STIX ID: report--9a31fac7-a305-5015-8b15-ee7ea99c3c89

Feed Name: Security Boulevard

Threat Score
70/100

Date Published: 2026-02-16

Date Updated: 2026-04-22

Author: Malwarebytes

...
...

The report describes ongoing ClickFix campaigns that trick users into executing malicious copy‑paste commands, now abusing nslookup to fetch a ZIP that extracts a Python script, stages a VBScript, and ultimately deploys ModeloRAT for remote control of Windows systems. It outlines the social-engineering lures (fake CAPTCHAs, updates, browser crashes, tutorial videos), the evasion of blocked mshta/PowerShell via nslookup-based payload delivery, and provides high-level defense guidance (avoid untrusted commands, slow down, minimize copy-paste, use real-time protection, and stay informed).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.