eSentire Details TAG-150’s ClickFix Chain Delivering DinDoor, DenoRAT and NightshadeC2

· Original article ↗

Summary

eSentire describes a TAG-150 infection at a finance customer, tracing a ClickFix command through DinDoor and DenoRAT to NightshadeC2, and reports that its analysts isolated the affected host.

Key points

  • The June 2026 incident began with a ClickFix lure prompting a Windows Run command that downloaded and executed an MSI installer.
  • A likely AI-generated PowerShell stage installed the Deno runtime and launched DinDoor, followed by DenoRAT.
  • DenoRAT established persistence, registered the host with its C2, and supported remote commands, file operations, screenshots, VNC-style control, and credential and wallet theft.
  • DenoRAT fetched a Python-based loader that decrypted and reflectively executed NightshadeC2 in memory.
  • DenoRAT also contains code for Chromium process injection and App-Bound Encryption bypass, though eSentire did not observe that behavior in this incident.
  • eSentire isolated the affected host and said it was developing detection content; it recommends disabling the Run prompt and using endpoint security tools.

Article Details

Attack Vectors
  • A ClickFix-style social engineering lure persuaded a user to execute a malicious command through the Windows Run prompt, initiating an MSI-based infection chain.
  • The MSI wrote and executed Griffin20.ps1, a likely AI-generated PowerShell stage that installed or located the Deno runtime and retrieved DinDoor.
  • DinDoor retrieved a stager that established registry persistence, registered the infected host with the C2, and fetched DenoRAT.
  • An observed DenoRAT C2 task executed PowerShell that downloaded a Python-based loader and an encrypted payload, leading to reflective execution of the final payload inside the Python process.
Defensive Notes
  • The response team isolated the affected host to contain the infection and assisted the customer with remediation.
  • Disable the Windows Run prompt through Group Policy: User Configuration > Administrative Templates > Start Menu and Taskbar > enable "Remove Run menu from Start Menu".
  • Provide phishing and security awareness training using real-world scenarios.
  • Use a 24/7 multi-signal MDR provider for visibility, threat hunting, disruption, and rapid response; the article recommends NGAV or EDR as a minimum.
  • The browser DLL-injection capability was present in the malware but was not observed in this incident.
  • The malware skips browser DLL injection when ESET is detected. The researchers suggest this may reflect attacker testing against security products, rather than demonstrating confirmed detection effectiveness.

Indicators of compromise

TypeIndicatorContext
DOMAINcolumbnezhjdq[.]comClickFix domain listed in the attack-chain IOC table.
DOMAINsmallsmokik[.]comNightshadeC2 C2 server identified as a dead-drop in the IOC table.
DOMAINwebstizkgao[.]comC2 server used by DinDoor, the DenoRAT stager, and DenoRAT.
SHA2561f233db3e59051811e16c65e32121f69dd80e91567002978e47a613a5a4903b0PowerShell task code that downloads and executes the install.pyc loader.
SHA2563dffe05d9cc49b2598d743301a8991965056d97bb8d429de461ed66c0dbde28bAnalyzed DenoRAT payload.
SHA2564ac3e1ecd2c4745f2e846ec7655b92234ee92068bffc7690c3f0184dc25c71daGriffin20.ps1 PowerShell stage that installs or locates Deno and launches DinDoor.
SHA2566103228087aaee53f37db88ab7aa1e7e5dd8c27a395bef7e3af985774a888c94C2 exec-ps task contents containing PowerShell used to decrypt and execute NightshadeC2.
SHA2567682e9ac86ff47cc198812719ca54e169c3cb21ce584ad2a278a640f4833de46DenoRAT stager responsible for persistence, host registration, and fetching DenoRAT.
SHA256a06d514a34d2ab08c3a13a58056827c50ba9bf01b68ca4b2cecb4e1462af53faSecond-stage Python script responsible for decrypting and executing NightshadeC2 in memory.
SHA256b4fd836b82f2d8daf8b90a95046987e993e5687707fc57b527a8145d865e3fdcEncrypted NightshadeC2 payload decrypted and executed by the Python loader.
SHA256c1e0a0543b12c64726f8bb36389010d7f35e57993a22ce5b73c56b9cc2a87a00NightshadeC2 payload reflectively mapped into the Python process.
SHA256c2cdf1ecd6684bbcef0405444a570a76e9589bbd563476b08788bde34d83b511Decompiled Python stager that decrypts and executes the next loader stage.
SHA256e0dd60bb3a409029988db6a10cb1e36586c2636da9eff3a3587bc38473fde54bCompiled install.pyc stager retrieved through DenoRAT tasking to load NightshadeC2.
SHA256ece42baaca7524460cc5ffc9ae94c2a634a67610decdd2bdc8f134c36fa2dd6cDinDoor launcher that retrieves and evaluates the next-stage stager.
SHA256fa0d1adb545881a2d8a508191961a9fd39485c4ac2a0f20ad8e2f931dc45c9efReflective PE loader shellcode executed by the Python loader.
URLhxxp[:]//webstizkgao[.]comC2 proxy URL embedded in the hard-coded authorization tokens used by the stager and DenoRAT.
URLhxxp[:]//webstizkgao[.]com/healthC2 health-check endpoint.
URLhxxp[:]//webstizkgao[.]com/message-eventDenoRAT C2 endpoint for receiving tasks and exfiltrating information.
URLhxxp[:]//webstizkgao[.]com/userC2 endpoint used to register infected devices.
URLhxxps[:]//cktdpnuwztdn[.]columbnezhjdq[.]comURL in the malicious ClickFix command that initiated the MSI-based infection chain.

MITRE ATT&CK

T1005 · Data from Local SystemDenoRAT supports collecting local cryptocurrency-wallet and Telegram data and retrieving C2-specified files.T1027 · Obfuscated Files or InformationThe stager and DenoRAT used JavaScript obfuscation; the Python loader and final payload were encrypted.T1027.007 · Dynamic API ResolutionThe reflective loader used DJB2 hashes to resolve module addresses, required exports, and payload imports.T1033 · System Owner/User DiscoveryThe stager sent the victim's username during registration, and DenoRAT collected it through sysinfo.T1041 · Exfiltration Over C2 ChannelDenoRAT transmitted host information to its C2 through POST requests to /message-event and supports stolen-data and file exfiltration.T1055.001 · Dynamic-link Library InjectionDenoRAT contains an unobserved capability to inject a C2-supplied DLL into a suspended browser using VirtualAllocEx, WriteProcessMemory, VirtualProtectEx, and CreateRemoteThread.T1057 · Process DiscoveryThe unobserved browser-injection capability enumerated browser processes using CreateToolhelp32Snapshot, Process32First, and Process32Next.T1059.001 · PowerShellPowerShell initiated the infection, installed Deno, established persistence, and executed the observed Python-loader delivery task.T1059.003 · Windows Command ShellDenoRAT supports remote command execution through cmd.exe /c and interactive cmd sessions.T1059.006 · PythonA Python-based loader decrypted the final payload and executed reflective loader shellcode inside its process.T1059.007 · JavaScriptDinDoor evaluates fetched JavaScript, while DenoRAT can execute C2-supplied Deno-JavaScript through temporary .mjs files.T1071.001 · Web ProtocolsDenoRAT used HTTP GET and POST requests for C2 task retrieval, registration, health checks, and information transmission.T1082 · System Information DiscoveryDenoRAT's sysinfo task collected hostname, domain, operating-system details, hardware counts, memory, and privilege information.T1083 · File and Directory DiscoveryDenoRAT supports enumerating drives and listing files and directories in C2-specified paths.T1105 · Ingress Tool TransferThe chain downloaded an MSI, Deno-based stages, a Python loader, and an encrypted NightshadeC2 payload.T1113 · Screen CaptureDenoRAT can capture the desktop through user32/gdi32 and send a base64-encoded JPEG to the C2.T1140 · Deobfuscate/Decode Files or InformationThe loader decrypted an RC4-protected Python stage and an AES-256-CBC-protected NightshadeC2 payload before execution.T1204 · User ExecutionThe ClickFix lure persuaded the user to run a malicious command through the Windows Run prompt.T1518.001 · Security Software DiscoveryDenoRAT checked specific installation directories to identify antivirus products and checked for ESET before browser DLL injection.T1539 · Steal Web Session CookieDenoRAT's stealer task supports theft of browser cookies.T1547.001 · Registry Run Keys / Startup FolderThe stager created an HKCU Run value named 1330705b to launch the persisted DinDoor script through Deno.T1555.003 · Credentials from Web BrowsersDenoRAT supports Chromium- and Gecko-based browser credential theft, including functionality supporting Chromium App-Bound Encryption bypass.T1555.005 · Password ManagersDenoRAT targets named password-manager browser extensions for exfiltration.T1564.003 · Hidden WindowPowerShell commands used WindowStyle Hidden, and the persistence command invoked conhost.exe with --headless.T1620 · Reflective Code LoadingThe Python loader executed shellcode that reflectively mapped NightshadeC2 into the current process, fixed imports, and invoked its entrypoint.

Threat Actors

Malware

Vendors

Products

1Password1Password aeblfdkhhhdcdjpifhhbdiojplfjncoaAuroWalletAuroWallet cnmamaachppnkjgnildpdmkaakejnhaeAuthenticatorAuthenticator bhghoamapcdpbohphigoooaddinpkbaiAvastC:\Program Files\Avast Software AvastAVGC:\Program Files\AVG AVGAviraPasswordManagerAviraPasswordManager caljgklbbfbcjjanaijlacgncafpegllBinanceChainBinanceChain fhbohimaelbohpjbbldcngcnapndodjpBitAppWalletBitAppWallet fihkakfobkmkjojpchpfgcmhfjnmnfpiBitClipBitClip ijmpgkjfkbfhoebgogflfebnmejmfbmlBitdefenderC:\Program Files\Bitdefender BitdefenderBitwardenBitwarden nngceckbapebfimnlniiiahkandclblbBrowserPassBrowserPass naepdomgkenhinolocfifgehidddafchByoneByone nlgbhdfgdhgbiamfdfmbikcdghidoaddCarbon BlackC:\Program Files\VMware\Carbon Black VMware Carbon BlackCisco AMPC:\Program Files\Cisco\AMP Cisco AMP for EndpointsCisco AMP for EndpointsC:\Program Files\Cisco\AMP Cisco AMP for EndpointsCloverWalletCloverWallet nhnkbkgjikgcigadomkphalanndcapjkCoin98Coin98 aeachknmefphepccionboohckonoeemgCoinbaseWalletCoinbaseWallet hnfanknocfeofbddgcijnmhnfnkdnaadCommonKeyCommonKey chgfefjpcobfbnpmiokfjjaglahmndedComodoC:\Program Files\Comodo ComodoCrowdStrike FalconC:\Program Files\CrowdStrike CrowdStrike FalconCyanoWalletCyanoWallet dkdedlpgdmmkkfjabffeganieamfklkmCyanoWalletProCyanoWalletPro icmkfkmjoklfhlfdkkkgpnpldkgdmhoeCylanceC:\Program Files\Cylance CylanceCylance ProtectC:\Program Files\CylanceProtect Cylance ProtectDAppPlayDAppPlay lodccjjbdhfakaekdiahmedfbieldgikDashlaneDashlane fdjamakpfbbddfjaooikfcpapjohcfmgDenoin a Finance customer's environment. Further investigation found that the command installs DinDoor, a Deno-based loader, DenoRAT, a Deno-based Remote Access Trojan (RAT), and NightshadeC2, a sophisticated RAT andDiscordcryptocurrency wallets (extension and desktop based), password manager extensions, Telegram data and Discord token theftEdgeFigure 12 - Create target browser process suspendedDenoRAT creates named pipes that resemble legitimate Chrome or Edge named pipes, selecting the format based on the targeted browser process.EOSAuthenticatorEOSAuthenticator oeljdldpnmdbchonielidgobddffflalEQUALWalletEQUALWallet blnieiiffboillknjnepogjhkgnoapaceSentire MDR for EndpointTRU is closely monitoring campaigns involving DinDoor, DenoRAT, and NightshadeC2, and developing up-to-date detection content for eSentire MDR for Endpoint, eSentire MDR for Log, and eSentire MDR for Network.eSentire MDR for LogTRU is closely monitoring campaigns involving DinDoor, DenoRAT, and NightshadeC2, and developing up-to-date detection content for eSentire MDR for Endpoint, eSentire MDR for Log, and eSentire MDR for Network.eSentire MDR for NetworkTRU is closely monitoring campaigns involving DinDoor, DenoRAT, and NightshadeC2, and developing up-to-date detection content for eSentire MDR for Endpoint, eSentire MDR for Log, and eSentire MDR for Network.ESETAfter terminating browser processes, DenoRAT checks whether ESET is present on the host. If ESET is detected, the malware skips DLL injection entirely. This suggests the threat actors may have tested against AV/EDREternlEternl kmhcihpebfmpgmihbkipmjlmmioamekaExodusExodus aholpfdialjgjfhomihkjbmgjidlcdnoF-SecureC:\Program Files\F-Secure F-SecureGoogle Chromechrome.exeGuardaGuarda hpglfhgfnhbgpjdenjgmdgoeiappaflnHyconLiteClientHyconLiteClient bcopgchhojmggmffilplmbdicgaihlkpICONexICONex flpiciilemghbmfalicajoolhkkenfeliWalletiWallet kncchdigobghenbbaddojjnnaogfppfjKasperskyC:\Program Files\Kaspersky Lab KasperskyKeePassXCKeePassXC oboonakemofpalcgghocfoadofidjkkkKeeperKeeper bfogiafebfohielmmehodmfbbebbbpeiKeplrKeplr dmkamcknogkgcdfhhbddcghachkejeapKHCKHC hcflpincpppdclinealmandijcmnkbgnLastPassLastPass hdokiejnpimakedhajhdlcegeplioahdLeafWalletLeafWallet cihmoadaighcejopammfbmddcmdekcjeLiqualityWalletLiqualityWallet kpfopkelmapcoipemfendmdcghnegimnMaiarDeFiWalletMaiarDeFiWallet dngmlblcodfobpdpecaadgfbcggfjfnmMalwarebytesC:\Program Files\Malwarebytes MalwarebytesMathWalletMathWallet afbcbjpbpfadlkmhmclhkeeodmamcflcMcAfeeC:\Program Files\McAfee McAfeeMetaMaskMetaMask nkbihfbeogaeaoehlefnkodbefgpgknnMetaMask_edgeMetaMask_edge ejbalbakoplchlghecdalmeeeajnimhmMEWCXMEWCX nlbmnnijcnlegkjjpcfjclmcfggfefdmMicrosoft Defender AntivirusC:\Program Files\Windows Defender Microsoft Defender AntivirusMicrosoft Defender for EndpointC:\Program Files\Windows Defender Advanced Threat Protection Microsoft Defender for EndpointMicrosoft Windowsidentified a TAG-150 ClickFix infection chain that started with a malicious command executed through the Windows Run prompt and an MSI installer. The chain then leveraged a likely AI-generated PowerShell stage toMYKIMYKI bmikpgodpkclnkgmnpphehdgcimmidedNaboxWalletNaboxWallet nknhiehlklippafakaeklbeglecifhadNamiNami lpfcbjknijpeeillifnkikgncikgfhdoNashExtensionNashExtension onofpnbbkehpmmoabgpcpmigafmmnjhlNeoLineNeoLine cphhlgmgameodnhkjdmkpanlelnlohaoNiftyWalletNiftyWallet jbdaocneiiinmjbjlgalhcelgbejmnidNordPassNordPass fooolghllnmhmmndgjiamiiodkpenpbbNortonC:\Program Files\Norton NortonNortonPasswordManagerNortonPasswordManager admmjipmmciaobhojoghlmleefbicajgOneKeyOneKey infeboajgfhgbjpjbeppbkgnabfdkdafPanda SecurityC:\Program Files\Panda Security Panda SecurityPhantomWalletPhantomWallet bfnaelmomeimhlpmgjnjophhpkkoljpaPolymeshWalletPolymeshWallet jojhfeoedkpkglbfimdfabpdfjaoolafPowerShellthrough the Windows Run prompt and an MSI installer. The chain then leveraged a likely AI-generated PowerShell stage to install the Deno runtime and launch the next-stage Deno-based loader, DinDoor, followed byPythonDenoRAT ultimately functioned as a loader for NightshadeC2, receiving a task from the C2 that launched a Python-based in-memory loader to decrypt and execute the NightshadeC2 RAT/infostealer payload.RoboFormRoboForm pnlccmojcmeohlpggmfnbbiapkmbliobRoninWalletRoninWallet fnjhmkhhmkbjkkabndcnnogagogbneecSaturnWalletSaturnWallet nkddgncdjgjfcddamfgcmfnlhccnimigScoopThe script first sets PowerShell's execution policy to RemoteSigned and adds the Scoop shims directory, %USERPROFILE%\scoop\shims, to PATH. If winget is missing, it installs Scoop if needed, then uses Scoop to installSentinelOneC:\Program Files\SentinelOne SentinelOneSolletSollet fhmfendgdocmcbmfikdcogofphimnknoSophosC:\Program Files\Sophos SophosSplikitySplikity jhfjfclepacoldmjmkmdlmganfaalklbSteemKeychainSteemKeychain lkcjlnjfpbikmcmbachjpdbijejflpcmTelegramand credential theft, cryptocurrency wallets (extension and desktop based), password manager extensions, Telegram data and Discord token theftTerraStationTerraStation aiifbnbfobpmeekipheeijimdpnlpgppTezBoxTezBox mnfifefkajgofkcjkemidiaecocnkjehTrend MicroC:\Program Files\Trend Micro Trend MicroTrezorPasswordManagerTrezorPasswordManager imloifkgjagghnncjkhggdhalmcnfklkTronLinkTronLink ibnejdfjmmkpcnlpebklmnkoeoihofecTrustWalletTrustWallet egjidjbpglichdcondbcbdnbeeppgdphVMware Carbon BlackC:\Program Files\VMware\Carbon Black VMware Carbon Blackwingetpolicy to RemoteSigned and adds the Scoop shims directory, %USERPROFILE%\scoop\shims, to PATH. If winget is missing, it installs Scoop if needed, then uses Scoop to install winget. It then attempts to installWombatWombat amkmjjmmflddogmhpjloimipbofnfjihYoroiYoroi ffnbelfdoeiohenkjibnmadjiehjhajbZilPayZilPay klnaejjgbibmhlephnhpmaofohgkpgkdZohoVaultZohoVault igkpcodhieompeloncfnbekccinhapdb

Tools

Industries

Related Articles