PowerShell-triggered RAT payload on Windows
Malware Activity
Updated: 29.09.2026 23:59
· First: 29.09.2026 23:59
· 📰 1 src / 1 articles
· H score: 22
The PowerShell-triggered ClickFix chain deployed a remote access trojan (RAT) that gave operators remote desktop access, camera/audio capture, reconnaissance, and additional payload execution on Windows. The malware established persistence with a Run key and scheduled task named Canon Configuration Reader. Delivery used a malicious MSI and a modified DLL loaded through a legitimate signed application, helping the infection blend in. Later variants shifted from a Canon-signed host app to a Stardock-signed one while keeping the same payload.