CrocoRat Malware Exploits ClickFix and DNS Staging
Score: 8/10

CrocoRat Malware Exploits ClickFix and DNS Staging

CrocoRat is a Python-based remote access trojan and cryptocurrency stealer delivered via ClickFix social engineering and novel DNS TXT record payload staging.

Executive Summary

CrocoRat is an evolving threat identified in late 2026 that utilizes the 'ClickFix' technique to deceive users into executing malicious PowerShell commands via the Windows Run dialog. The malware is characterized by its use of DNS TXT records to stage payloads, avoiding traditional clipboard-based detection. It features a victim-aware execution model that distinguishes between domain-joined organizational systems and standalone personal machines to tailor its post-exploitation activities.

On organizational systems, the malware prioritizes persistent access through a remote access trojan (RAT) component. Standalone systems are subjected to a broader theft workflow targeting browser credentials, session tokens, and cryptocurrency wallet recovery phrases across 22 wallet families. The campaign shows high operational maturity with rotated infrastructure, encrypted payloads, and a portable Python runtime that reduces dependency on host environments.

Attribution points toward a Russian-speaking developer or operator based on high-quality Russian-language code comments and professional Windows tradecraft. The threat is actively maintained, with significant infrastructure and payload shifts observed between August and September 2026, necessitating behavioral-based detection rather than reliance on static indicators.

Key Details

Threat Name

CrocoRat

Affects

—

Adversary

CrocoRat

Malware/Tools

CrocoRat, jumitetwska, knutkcp, lcyfagci

Report Score

8out of 10
Quality Score
Good
IOC Quality8
TTP Details9
Detection Guidance7
Enterprise Relevance9
Clarity & Structure8
Technical Depth9

Sources