WatchGuard has revealed new research from its Threat Lab into an active campaign combining ClickFix and EtherHiding to distribute NightshadeC2/CastleRAT, a remote access Trojan associated with the Russian Malware-as-a-Service operator TAG-150 and used to distribute malware.
The analysis, carried out by Euler Neto, a researcher at the company, shows a particularly selective campaign from a geographical point of view. Attackers target Windows users in the United States, Canada, the United Kingdom, Ireland, Australia and New Zealand and combine social engineering techniques with the use of legitimate services and technologies to conceal the different phases of the attack and make malware difficult to detect.
The research thus reflects a particularly relevant trend: cybercriminals are increasingly integrating their activity within commonly used web, cloud and blockchain infrastructures, which can make it difficult to identify malicious behavior when each element is observed in isolation and malware is distributed through apparently legitimate services.
Fake verifications to deceive the user
The attack begins on previously compromised WordPress websites. Cybercriminals insert malicious content that displays false verifications designed to convince the user to execute a command on their own computer. This technique, known as ClickFix, is based precisely on making the victim believe that they must perform a certain action to solve a problem or complete a legitimate verification. In this case, the objective is to get it to execute a PowerShell command that allows the infection to progress and download the malware.
Additionally, WatchGuard has verified that malicious content is not displayed indiscriminately. The campaign uses the user’s location to select its targets and loads content only when it detects connections from the six English-speaking countries identified in the research.
Blockchain and cloud services to hide activity
The campaign combines ClickFix with EtherHiding, a technique in which attackers use blockchain infrastructure as part of the malware distribution process.
Specifically, they use Ethereum Sepolia smart contracts to recover encrypted information necessary to continue the attack. From there, the infection chain also uses services such as Cloudflare R2, as well as technologies such as PowerShell and Python.
Additionally, WatchGuard has identified successive changes to the campaign aimed at changing the way malicious content is distributed and making it more difficult to detect.
One of the most significant elements of the analysis is precisely the combination of numerous legitimate services within the same operation. In addition to WordPress, Ethereum and Cloudflare, researchers have observed the use of Steam Community in a later phase to obtain information related to the malware control infrastructure.
Malware can record keystrokes, access clipboard contents, take screenshots, or hijack browser sessions
In this way, attackers mix their activity with widely used platforms and technologies to make different parts of the chain appear legitimate separately.
A Trojan with extensive surveillance capabilities
The ultimate goal of the campaign is to install NightshadeC2/CastleRAT, a remote access Trojan that provides attackers with extensive capabilities to monitor compromised computers and obtain information. Malware can log keystrokes, access clipboard contents, take screenshots, hijack browser sessions, steal credentials, and allow remote access to the device.
It can also target information stored in browsers, password managers, cryptocurrency wallets, and authentication extensions.
The investigation has also identified a mechanism that checks the language configured in the system and prevents certain phases of the malware from continuing to run on computers associated with several countries of the Commonwealth of Independent States (CIS).
The campaign highlights how threat actors are combining geographic targeting, social engineering, and legitimate digital infrastructures to build attack chains that are harder to recognize and track.
