securityonline.info 7/24/2026, 10:00:58 AM · external

Financial Firm Hit by ClickFix, DenoRAT and NightshadeC2

Financial Firm Hit by ClickFix, DenoRAT and NightshadeC2
CyberSIXT Evidence Panel
Threat Actor

A recent cyberattack targeting a financial institution utilized a ClickFix social engineering lure, revealing an evolving TAG-150 attack chain. Conducted in June 2026 by the eSentire Threat Response Unit, this attack used DenoRAT malware and NightshadeC2 to compromise systems. Key details include:

The attack employs a series of strategies including bypassing security measures to install and execute malicious scripts and exploit user trust. Defenders are advised to monitor for unauthorized Deno installations and be aware of ClickFix tactics to improve cybersecurity.

View full article

Article by CyberSIXT