216.73.216.6

59 Victims, Zero Authentication: A ClickFix Campaign Force-Installs a Chrome Extension Banking Stealer and Leaves the Entire C2 Wide Open

· Published 14/04/2026 13:56 · Modified 14/04/2026 14:20

Export JSON

Essential information

Published
14/04/2026 13:56
Modified
14/04/2026 14:20
Tags
2026-04-14 banking-stealer clickfix credential-theft session hijacking
Related entities
12 observables, 1 intrusion sets (apt), 20 techniques (mitre), 2 malware, 8 others

Description

A Brazilian banking fraud operation leveraging social engineering was discovered through a community tip, exposing a completely unauthenticated command-and-control infrastructure. The campaign deploys a malicious Chrome extension masquerading as a Banco Central do Brasil tool, force-installed via Chrome Cloud Management enrollment tokens. The extension achieves zero antivirus detections while targeting eight Brazilian financial institutions. At investigation time, 59 machines were compromised with seven active connections. The operator's C2 server exposed all endpoints without authentication, including admin panels, live victim screenshots, stolen credentials in cleartext, and intercepted Pix payment data. Attribution was established through WHOIS records revealing the operator's real name, CPF, and email address. The operation specifically targeted Northern Brazilian regional banks and credit cooperatives, with evidence of compromising a school fund account.

External references