From ClickFix to MaaS: Exposing a Modular Windows RAT and Its Admin Panel
A modular Windows remote access Trojan (RAT) campaign, named ClickFix, targets Windows users via malicious MSI installers. The malware is NodeJS-based and uses dynamic in-memory loading of core modules and communication protocols after connecting to its command-and-control (C2) server. It employs gRPC streaming over the Tor network to maintain persistent and masked bidirectional communication channels. An operational security failure exposed the malware's admin panel protocol, revealing a malware-as-a-service (MaaS) backend that manages multiple operators and automates cryptocurrency asset tracking. The RAT supports full functionality including shell command execution and wallet tracking, while evading static signature detection through dynamic code execution.
AI Analysis
Technical Summary
The ClickFix campaign delivers a NodeJS-based infostealer and RAT to Windows systems via malicious MSI installers. Its modular architecture loads core stealing modules and communication protocols dynamically in-memory only after establishing a C2 connection, minimizing forensic footprints. Communication is routed over Tor using gRPC streaming to maintain stealthy, persistent channels. An operational security lapse exposed the server-side admin panel protocol definitions, revealing a MaaS backend designed to support multiple operators and automate cryptocurrency theft tracking. The malware executes malicious logic dynamically as strings in-memory, bypassing static detection and enabling full RAT capabilities such as shell command execution and wallet tracking.
Potential Impact
This malware enables attackers to remotely control infected Windows systems with full RAT functionality, including executing shell commands and stealing cryptocurrency wallet information. Its use of dynamic in-memory loading and Tor-based communication channels complicates detection and forensic analysis. The MaaS backend allows multiple operators to leverage the malware, potentially increasing the scale and automation of attacks targeting cryptocurrency assets.
Mitigation Recommendations
No official patch or remediation is currently available for this malware. Mitigation should focus on preventing infection by blocking delivery vectors such as malicious MSI installers and monitoring for indicators of compromise including the provided domains, URLs, and file hashes. Network defenses should consider blocking or monitoring Tor network traffic and gRPC streaming connections associated with this threat. Since the malware uses dynamic in-memory execution, traditional signature-based detection may be insufficient; behavioral and heuristic detection methods are recommended. Review and strengthen operational security to prevent exposure of backend infrastructure.
Indicators of Compromise
- domain: yuhvgbzsa66biqeatbmdvfo5b5jjefcmz5t2vjuvco5qtdkshfpabyid.onion
- hash: 519d5f0350f7880559ad6ca51eb9c4e91ffe2046b635b58ada4b7269b775bb89
- url: https://bull-run.fun/
- url: https://spot-wave.fun/
- url: http://yuhvgbzsa66biqeatbmdvfo5b5jjefcmz5t2vjuvco5qtdkshfpabyid.onion:50051
- url: https://cloud-verificate.com/NodeServer-Setup-Full.msi
From ClickFix to MaaS: Exposing a Modular Windows RAT and Its Admin Panel
Description
A modular Windows remote access Trojan (RAT) campaign, named ClickFix, targets Windows users via malicious MSI installers. The malware is NodeJS-based and uses dynamic in-memory loading of core modules and communication protocols after connecting to its command-and-control (C2) server. It employs gRPC streaming over the Tor network to maintain persistent and masked bidirectional communication channels. An operational security failure exposed the malware's admin panel protocol, revealing a malware-as-a-service (MaaS) backend that manages multiple operators and automates cryptocurrency asset tracking. The RAT supports full functionality including shell command execution and wallet tracking, while evading static signature detection through dynamic code execution.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The ClickFix campaign delivers a NodeJS-based infostealer and RAT to Windows systems via malicious MSI installers. Its modular architecture loads core stealing modules and communication protocols dynamically in-memory only after establishing a C2 connection, minimizing forensic footprints. Communication is routed over Tor using gRPC streaming to maintain stealthy, persistent channels. An operational security lapse exposed the server-side admin panel protocol definitions, revealing a MaaS backend designed to support multiple operators and automate cryptocurrency theft tracking. The malware executes malicious logic dynamically as strings in-memory, bypassing static detection and enabling full RAT capabilities such as shell command execution and wallet tracking.
Potential Impact
This malware enables attackers to remotely control infected Windows systems with full RAT functionality, including executing shell commands and stealing cryptocurrency wallet information. Its use of dynamic in-memory loading and Tor-based communication channels complicates detection and forensic analysis. The MaaS backend allows multiple operators to leverage the malware, potentially increasing the scale and automation of attacks targeting cryptocurrency assets.
Defensive Guidance
No official patch or remediation is currently available for this malware. Mitigation should focus on preventing infection by blocking delivery vectors such as malicious MSI installers and monitoring for indicators of compromise including the provided domains, URLs, and file hashes. Network defenses should consider blocking or monitoring Tor network traffic and gRPC streaming connections associated with this threat. Since the malware uses dynamic in-memory execution, traditional signature-based detection may be insufficient; behavioral and heuristic detection methods are recommended. Review and strengthen operational security to prevent exposure of backend infrastructure.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.netskope.com/blog/from-clickfix-to-maas-exposing-a-modular-windows-rat-and-its-admin-panel"]
- Adversary
- null
- Pulse Id
- 6a8592950ee0e8d05fc1bec9
- Threat Score
- null
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domainyuhvgbzsa66biqeatbmdvfo5b5jjefcmz5t2vjuvco5qtdkshfpabyid.onion | — |
Hash
| Value | Description | Copy |
|---|---|---|
hash519d5f0350f7880559ad6ca51eb9c4e91ffe2046b635b58ada4b7269b775bb89 | — |
Url
| Value | Description | Copy |
|---|---|---|
urlhttps://bull-run.fun/ | — | |
urlhttps://spot-wave.fun/ | — | |
urlhttp://yuhvgbzsa66biqeatbmdvfo5b5jjefcmz5t2vjuvco5qtdkshfpabyid.onion:50051 | — | |
urlhttps://cloud-verificate.com/NodeServer-Setup-Full.msi | — |
Threat ID: 6a85d141acd9273b4948a8d3
Added to database: 08/19/2026, 15:52:33 UTC
Last enriched: 08/19/2026, 17:54:58 UTC
Last updated: 08/19/2026, 19:46:06 UTC
Views: 10
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.