logo

ClickFix Campaign Generated Via AI Delivers SmartRAT

ID: b714f4d1-1542-58be-8271-dcf5f51e0404

STIX ID: report--b714f4d1-1542-58be-8271-dcf5f51e0404

Feed Name: Security Boulevard

Threat Score
75/100

Date Published: 2026-06-17

Date Updated: 2026-06-18

Author: Shruti Dixit (Security Researcher)

...
...

Zscaler ThreatLabz reports an AI-assisted ClickFix campaign using typosquatting domains (e.g., cartaobb.com) to deliver SmartRAT, a PowerShell-based banking RAT that supports encrypted C2, remote control, keylogging, fake bank overlays and QR-swap fraud; the chain uses a clipboard PowerShell run command and staged droppers, persists via scheduled tasks or a SYSTEM service, communicates to C2 over TCP:51888, and exposes IOCs and a flawed web C2 panel authentication.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.