A recent cyberattack targeting a financial institution utilized a ClickFix social engineering lure, revealing an evolving TAG-150 attack chain. Conducted in June 2026 by the eSentire Threat Response Unit, this attack used DenoRAT malware and NightshadeC2 to compromise systems. Key details include:
- **Malware Family:** DinDoor, DenoRAT, NightshadeC2
- **Threat Actor:** TAG-150
- **Victims:** Finance sector
- **Delivery Vector:** Social engineering via ClickFix, Windows Run prompt, MSI installer
The attack employs a series of strategies including bypassing security measures to install and execute malicious scripts and exploit user trust. Defenders are advised to monitor for unauthorized Deno installations and be aware of ClickFix tactics to improve cybersecurity.