Executive Summary
CrocoRat is an evolving threat identified in late 2026 that utilizes the 'ClickFix' technique to deceive users into executing malicious PowerShell commands via the Windows Run dialog. The malware is characterized by its use of DNS TXT records to stage payloads, avoiding traditional clipboard-based detection. It features a victim-aware execution model that distinguishes between domain-joined organizational systems and standalone personal machines to tailor its post-exploitation activities.
On organizational systems, the malware prioritizes persistent access through a remote access trojan (RAT) component. Standalone systems are subjected to a broader theft workflow targeting browser credentials, session tokens, and cryptocurrency wallet recovery phrases across 22 wallet families. The campaign shows high operational maturity with rotated infrastructure, encrypted payloads, and a portable Python runtime that reduces dependency on host environments.
Attribution points toward a Russian-speaking developer or operator based on high-quality Russian-language code comments and professional Windows tradecraft. The threat is actively maintained, with significant infrastructure and payload shifts observed between August and September 2026, necessitating behavioral-based detection rather than reliance on static indicators.
