216.73.216.233

New Clickfix variant 'CrashFix' deploying Python Remote Access Trojan

· Published 05/02/2026 20:01 · Modified 05/02/2026 21:07

Export JSON

Essential information

Published
05/02/2026 20:01
Modified
05/02/2026 21:07
Tags
2026-02-05 browser extension crashfix modelorat obfuscation persistence python rat reconnaissance social engineering
Related entities
13 observables, 1 intrusion sets (apt), 2 malware

Description

A new evolution in the ClickFix campaign, dubbed , has been identified. This variant deliberately crashes victims' browsers and uses to lure users into executing malicious commands. The attack begins with a malicious ad redirecting users to install a harmful impersonating a legitimate ad blocker. The payload causes delayed browser issues and presents a fake security warning. It misuses the Windows utility finger.exe to execute malicious commands and downloads additional payloads, including a Python-based Remote Access Trojan (RAT). The RAT, named , establishes and performs extensive . The campaign targets domain-joined systems and employs multiple techniques to evade detection.

External references