A fake verification step can ask someone to run the command that compromises their own workstation. In an analysis published on 6 October 2026, Flare describes CrocoRat, Windows malware delivered through ClickFix. After a PowerShell command is pasted, the chain retrieves instructions through DNS TXT records and selects a path suited to the machine.
From a fake check to the clipboard
ClickFix presents a fictional problem, such as a CAPTCHA verification, and asks the user to follow steps that appear to repair the browser. The page places a command on the clipboard, then tells the user to open Run with Win+R and paste it.
Because the user pastes the command themselves, this can bypass some protections designed to block a downloaded file. It does not make ClickFix invisible: page activity, process behaviour, and executed commands can still be detected.
The role of DNS TXT records
In the chain Flare studied, the first PowerShell command queries TXT records to retrieve the next stage. This splits delivery into multiple phases and avoids putting the entire malicious payload in the first visible command.
A single TXT request is not enough to establish a compromise. Teams should look for context: an unexpected parent process, a command pasted from a browser, resolution of rare domains, and subsequent downloads or component execution.
Payloads that vary by host
Flare describes CrocoRat as a remote access trojan and cryptocurrency stealer. The chain can download a portable Python bundle and choose actions based on the detected environment. The report describes different paths for machines that appear corporate and personal.
These capabilities come from sample analysis and behaviour observed or inferred by the researchers. The report does not give an infection count or show that every module was deployed in every case.
How to respond to a ClickFix page
Do not paste a command from a web page into Run, even if it is presented as a verification or repair step. Close the tab, navigate to the service’s official address, and report the page to your IT team if you encountered it on a work device.
If you already ran an unexpected command, disconnect the device from the network according to your organisation’s process and contact security support. From another trusted device, change potentially exposed passwords and revoke sessions or tokens accessible from that workstation after your response team assesses them.
The Soclyde connection
Soclyde does not detect ClickFix or clean an infected device. A local-first vault can limit the impact of a reused password, but it cannot protect an active session or a token present on the workstation. Containment and revocation steps must be applied in the affected services.
The takeaway
CrocoRat abuses ClickFix logic: the victim pastes a command that then retrieves instructions through DNS TXT. Observed paths and payloads vary by host, and no victim estimate has been published. Do not run commands supplied by a webpage; if you already did, follow your organisation’s response procedure immediately. Read our infostealer guide to understand credential-theft risks.



