SOCLYDE logo
Current languageEN
Cybersecurity newsMalwareClickFixCredential theft

Crocorat uses clickfix and dns requests

A ClickFix lure prompts victims to run a Windows command; CrocoRat then retrieves instructions through DNS TXT and adapts its payload.

Published on

By Soclyde Team

A person closes a laptop while keeping a phone nearby

In summary

  • Flare describes CrocoRat as Windows malware delivered through ClickFix pages that place a command on the clipboard.
  • The first command queries DNS TXT records to retrieve the next stage of the infection.
  • Subsequent behaviour varies by environment; the report does not provide a victim count.

Explore next

Soclyde resources

Article contents

A fake verification step can ask someone to run the command that compromises their own workstation. In an analysis published on 6 October 2026, Flare describes CrocoRat, Windows malware delivered through ClickFix. After a PowerShell command is pasted, the chain retrieves instructions through DNS TXT records and selects a path suited to the machine.

From a fake check to the clipboard

ClickFix presents a fictional problem, such as a CAPTCHA verification, and asks the user to follow steps that appear to repair the browser. The page places a command on the clipboard, then tells the user to open Run with Win+R and paste it.

Because the user pastes the command themselves, this can bypass some protections designed to block a downloaded file. It does not make ClickFix invisible: page activity, process behaviour, and executed commands can still be detected.

The role of DNS TXT records

In the chain Flare studied, the first PowerShell command queries TXT records to retrieve the next stage. This splits delivery into multiple phases and avoids putting the entire malicious payload in the first visible command.

A single TXT request is not enough to establish a compromise. Teams should look for context: an unexpected parent process, a command pasted from a browser, resolution of rare domains, and subsequent downloads or component execution.

Payloads that vary by host

Flare describes CrocoRat as a remote access trojan and cryptocurrency stealer. The chain can download a portable Python bundle and choose actions based on the detected environment. The report describes different paths for machines that appear corporate and personal.

These capabilities come from sample analysis and behaviour observed or inferred by the researchers. The report does not give an infection count or show that every module was deployed in every case.

How to respond to a ClickFix page

Do not paste a command from a web page into Run, even if it is presented as a verification or repair step. Close the tab, navigate to the service’s official address, and report the page to your IT team if you encountered it on a work device.

If you already ran an unexpected command, disconnect the device from the network according to your organisation’s process and contact security support. From another trusted device, change potentially exposed passwords and revoke sessions or tokens accessible from that workstation after your response team assesses them.

The Soclyde connection

Soclyde does not detect ClickFix or clean an infected device. A local-first vault can limit the impact of a reused password, but it cannot protect an active session or a token present on the workstation. Containment and revocation steps must be applied in the affected services.

The takeaway

CrocoRat abuses ClickFix logic: the victim pastes a command that then retrieves instructions through DNS TXT. Observed paths and payloads vary by host, and no victim estimate has been published. Do not run commands supplied by a webpage; if you already did, follow your organisation’s response procedure immediately. Read our infostealer guide to understand credential-theft risks.

Frequently asked questions

How does the ClickFix lure launch CrocoRat?

The page displays a fake verification step and copies a command. It then prompts the victim to open Run with Win+R and paste the command themselves. This apparently voluntary action can bypass suspicion associated with a conventional download.

What do the DNS TXT requests do?

In the sample Flare analysed, PowerShell queries DNS TXT records to retrieve instructions and material for the next stage. DNS is used as a staged delivery channel; the report does not mean every TXT request is malicious.

Did CrocoRat steal passwords or cryptocurrency?

Flare describes remote-access-trojan and cryptocurrency-stealing capabilities, with payload paths that vary by host. The technical report does not provide a victim count or prove every capability was used on every infected machine.

References

Sources and references

Need advice?

Design your password strategy with Soclyde

Schedule a dedicated walkthrough with the team to see how local-first security adapts to your stack.

Talk with us

Keep reading