Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

From ClickFix to MaaS: Exposing a Modular Windows RAT and Its Admin Panel

0
Medium
Published: 08/19/2026 (08/19/2026, 11:25:09 UTC)
Source: AlienVault OTX General

Description

A modular Windows remote access Trojan (RAT) campaign, named ClickFix, targets Windows users via malicious MSI installers. The malware is NodeJS-based and uses dynamic in-memory loading of core modules and communication protocols after connecting to its command-and-control (C2) server. It employs gRPC streaming over the Tor network to maintain persistent and masked bidirectional communication channels. An operational security failure exposed the malware's admin panel protocol, revealing a malware-as-a-service (MaaS) backend that manages multiple operators and automates cryptocurrency asset tracking. The RAT supports full functionality including shell command execution and wallet tracking, while evading static signature detection through dynamic code execution.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/19/2026, 17:54:58 UTC

Technical Analysis

The ClickFix campaign delivers a NodeJS-based infostealer and RAT to Windows systems via malicious MSI installers. Its modular architecture loads core stealing modules and communication protocols dynamically in-memory only after establishing a C2 connection, minimizing forensic footprints. Communication is routed over Tor using gRPC streaming to maintain stealthy, persistent channels. An operational security lapse exposed the server-side admin panel protocol definitions, revealing a MaaS backend designed to support multiple operators and automate cryptocurrency theft tracking. The malware executes malicious logic dynamically as strings in-memory, bypassing static detection and enabling full RAT capabilities such as shell command execution and wallet tracking.

Potential Impact

This malware enables attackers to remotely control infected Windows systems with full RAT functionality, including executing shell commands and stealing cryptocurrency wallet information. Its use of dynamic in-memory loading and Tor-based communication channels complicates detection and forensic analysis. The MaaS backend allows multiple operators to leverage the malware, potentially increasing the scale and automation of attacks targeting cryptocurrency assets.

Defensive Guidance

No official patch or remediation is currently available for this malware. Mitigation should focus on preventing infection by blocking delivery vectors such as malicious MSI installers and monitoring for indicators of compromise including the provided domains, URLs, and file hashes. Network defenses should consider blocking or monitoring Tor network traffic and gRPC streaming connections associated with this threat. Since the malware uses dynamic in-memory execution, traditional signature-based detection may be insufficient; behavioral and heuristic detection methods are recommended. Review and strengthen operational security to prevent exposure of backend infrastructure.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.netskope.com/blog/from-clickfix-to-maas-exposing-a-modular-windows-rat-and-its-admin-panel"]
Adversary
null
Pulse Id
6a8592950ee0e8d05fc1bec9
Threat Score
null

Indicators of Compromise

Domain

ValueDescriptionCopy
domainyuhvgbzsa66biqeatbmdvfo5b5jjefcmz5t2vjuvco5qtdkshfpabyid.onion

Hash

ValueDescriptionCopy
hash519d5f0350f7880559ad6ca51eb9c4e91ffe2046b635b58ada4b7269b775bb89

Url

ValueDescriptionCopy
urlhttps://bull-run.fun/
urlhttps://spot-wave.fun/
urlhttp://yuhvgbzsa66biqeatbmdvfo5b5jjefcmz5t2vjuvco5qtdkshfpabyid.onion:50051
urlhttps://cloud-verificate.com/NodeServer-Setup-Full.msi

Threat ID: 6a85d141acd9273b4948a8d3

Added to database: 08/19/2026, 15:52:33 UTC

Last enriched: 08/19/2026, 17:54:58 UTC

Last updated: 08/19/2026, 19:46:06 UTC

Views: 10

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses