Tech News
← Home  ·  All topics

Cryptocurrency Stealer

1 GoKawiil brief on this topic

ClickFix malware campaigns hide payloads behind DNS lookups, researchers find

Security researchers at Flare identified a ClickFix social-engineering campaign distributing the CrocoRat remote access Trojan and cryptocurrency stealer via a misspelled domain showing a fake house-wiring image. Instead of fetching malware directly, the pasted PowerShell command queries an attacker-controlled DNS TXT record, which returns instructions for the next stage of the attack.