ClickFix Campaign Generated Via AI Delivers SmartRAT
ID: b714f4d1-1542-58be-8271-dcf5f51e0404
STIX ID: report--b714f4d1-1542-58be-8271-dcf5f51e0404
Feed Name: Security Boulevard
Threat Score
Zscaler ThreatLabz reports an AI-assisted ClickFix campaign using typosquatting domains (e.g., cartaobb.com) to deliver SmartRAT, a PowerShell-based banking RAT that supports encrypted C2, remote control, keylogging, fake bank overlays and QR-swap fraud; the chain uses a clipboard PowerShell run command and staged droppers, persists via scheduled tasks or a SYSTEM service, communicates to C2 over TCP:51888, and exposes IOCs and a flawed web C2 panel authentication.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
