Back to Intelligence

ClickFix-Custom-GPT Malvertising Chain Delivers Lumma, SectopRAT & AMOS + JSCeal V8 Bytecode Stealer: OTX Pulse Analysis — Enterprise Detection Pack

SA
Security Arsenal Team
September 30, 2026
11 min read

Two AlienVault OTX pulses published 2026-09-29/30 converge on a single theme dominating the credential-theft landscape in late 2026: infostealers are winning initial access through trusted platforms, and evading defenders by compiling themselves out of sight.

Pulse 1 documents an active malvertising-to-RAT chain. Threat actors purchase sponsored Google search results that route victims to attacker-created ChatGPT Custom GPTs impersonating legitimate models. The GPT redirects the victim to a malicious Google Sites page hosting a fake Cloudflare CAPTCHA — a textbook ClickFix lure. The victim is socially engineered into pasting and executing an obfuscated PowerShell command, which triggers a multi-stage chain delivering Lumma Stealer, SectopRAT, MacSync, and AMOS (the macOS-focused payloads confirm cross-platform targeting). Pulse tags call out canon sideloading and PowerShell obfuscation — indicating DLL side-loading via legitimate Canon binaries and heavily encoded script stages. This is an evolution of the ClearFake/FakeUpdate playbook: the initial access broker monetizes the trusted reputation of Google Sites and OpenAI infrastructure rather than standing up disposable domains.

Pulse 2 is a deep technical look at JSCeal, a cryptocurrency-focused stealer delivered as compiled V8 bytecode via Node.js — a significant anti-analysis leap. Check Point Research built a fully static deobfuscation pipeline to defeat its layered protections: RC4-encrypted strings, control-flow flattening, and proxy functions injected via javascript-obfuscator. Because traditional JS deobfuscators fail against V8 bytecode, JSCeal effectively blunts sandbox and static triage. The .info domain indicators (console.info, profile.info) point to its C2/exfil tier.

Collective picture: Initial-access brokers are laundering traffic through Big Tech trust (Google, OpenAI), executing fileless ClickFix stages in memory, and shipping final payloads in compiled formats (V8 bytecode, side-loaded DLLs) that defeat signature-based detection. The objective in both cases is the same: bulk credential, session cookie, and cryptocurrency wallet theft feeding dark web credential markets. Stolen identity telemetry harvested by Lumma and JSCeal-class stealers lands on darknet logs markets within hours of infection — which is why this briefing carries the darkweb-credentials classification.

Threat Actor / Malware Profile

Lumma Stealer (MaaS)

  • Distribution: ClickFix fake CAPTCHA pages, malvertising, Custom GPT redirection, YouTube/Discord lures
  • Payload behavior: Steals browser credentials, cookies/session tokens, autofill data, crypto wallets, 2FA extension data, and Telegram sessions; exfiltrates to C2 over HTTPS
  • C2: Hardcoded domains with rotating infrastructure; typical beaconing on first execution
  • Persistence: Registry Run keys and scheduled tasks on some builds; often single-shot with rapid exfil
  • Anti-analysis: Packed binaries, string encryption, sandbox checks

SectopRAT (aka ArechClient)

  • Distribution: Same ClickFix chain; frequently deployed alongside stealers as a second stage
  • Payload behavior: Hidden browser session capability — creates a concealed browser instance operators use to hijack authenticated sessions (bypassing MFA via token theft), enabling streaming of victim screens
  • C2: Encrypted TCP/HTTPS channels; .NET-based
  • Anti-analysis: .NET obfuscation, config encryption

AMOS / MacSync (macOS)

  • Distribution: ClickFix terminal-command lures targeting macOS users via fake CAPTCHA / "fix this issue" prompts
  • Payload behavior: AppleScript/bash execution chains; Keychain, browser, and crypto wallet theft on macOS
  • Significance: Confirms this campaign is cross-platform — Windows and macOS users hit by the same Google Ads infrastructure

JSCeal (V8 Bytecode Stealer)

  • Distribution: Trojanized Node.js packages / cracked software bundles
  • Payload behavior: Browser credential and cookie theft with cryptocurrency wallet focus (browser extension wallets, exchange sessions)
  • C2: .info TLD infrastructure (console.info, profile.info indicators)
  • Persistence: Node.js process masquerading; startup entries in some variants
  • Anti-analysis (standout): Compiled to V8 bytecode rather than readable JS; layered javascript-obfuscator protections (RC4-encrypted strings, control-flow flattening, proxy function indirection). Check Point's static View8-pseudocode pipeline was required — meaning most automated sandboxes see nothing.

IOC Analysis

The pulses contain two indicator classes with different operational lifetimes:

File hashes (30+ SHA256/MD5) — payload and stage samples for Lumma/SectopRAT/AMOS and JSCeal. Hashes are the lowest-fidelity indicator for MaaS families (repacked daily), but remain useful for: retro-hunting EDR telemetry over the past 30–90 days, email gateway/DLP matches, and blocking known-bad samples at proxy and endpoint. Load them into your EDR block list and SIEM threat-intel matching. Do not rely on them alone.

Domains (console.info, profile.info) — JSCeal C2-tier infrastructure. Domains have better shelf life. Sinkhole/block at DNS, alert on any resolution events, and hunt historical DNS logs going back at least 30 days. Treat any .info resolution from non-browser processes (especially node.exe) as high-signal.

Behavioral artifacts (highest value) — because hashes rot and domains rotate, the durable detections are: (1) ClickFix pattern — a browser spawning PowerShell/cmd containing paste-style Base64 or iex/Invoke-Expression with download cradles; (2) DLL side-loading of legitimate Canon-signed binaries; (3) node.exe executing non-JS/binary blobs or making connections to .info TLDs; (4) browser credential store access (Login Data, Local State) by non-browser processes.

Tooling to decode/verify: VirusTotal/OTX lookups for hash reputation; View8 or Check Point's published static pipeline for V8 bytecode analysis; CyberChef for the RC4-encrypted string layers once keys are extracted; urlscan.io for Google Sites lure pages.

Detection Engineering

YAML
---
title: ClickFix Fake CAPTCHA Clipboard PowerShell Execution
id: 8f2a1c4e-7b3d-4e6a-9c1f-2a5b8d0e3f71
status: experimental
description: Detects ClickFix social engineering where a browser process spawns PowerShell/cmd with encoded or paste-style download cradle commands, consistent with Custom GPT / Google Sites fake CAPTCHA lures delivering Lumma, SectopRAT, or AMOS.
author: Security Arsenal Threat Intelligence
references:
  - https://www.huntress.com/blog/chatgpt-custom-gpts-clickfix-rat
date: 2026/09/30
logsource:
  category: process_creation
  product: windows
level: high
tags:
  - attack.execution
  - attack.t1059.001
  - attack.t1204
detection:
  selection_parent:
    ParentImage|endswith:
      - '\chrome.exe'
      - '\msedge.exe'
      - '\firefox.exe'
      - '\brave.exe'
  selection_child:
    Image|endswith:
      - '\powershell.exe'
      - '\pwsh.exe'
      - '\cmd.exe'
      - '\mshta.exe'
      - '\rundll32.exe'
  selection_flags:
    CommandLine|contains:
      - ' -enc'
      - ' -ec '
      - 'FromBase64String'
      - 'Invoke-Expression'
      - 'iex '
      - 'Invoke-WebRequest'
      - 'DownloadString'
      - 'Start-BitsTransfer'
      - 'curl '
      - 'Hidden'
  condition: selection_parent and selection_child and selection_flags
falsepositives:
  - Rare IT-driven browser-launched scripts
---
title: Node.js Execution of Compiled V8 Bytecode / Suspicious Node Network Activity (JSCeal)
id: 3c7d9e2a-5f1b-4a8c-b6d4-9e0f1a2c3b45
status: experimental
description: Detects node.exe spawning from non-development locations, loading bytecode-style payloads, or accessing browser credential stores — consistent with JSCeal stealer delivered as compiled V8 bytecode.
author: Security Arsenal Threat Intelligence
references:
  - https://research.checkpoint.com/2026/breaking-the-seal-static-deobfuscation-of-jsceals-compiled-v8-bytecode/
date: 2026/09/30
logsource:
  category: process_creation
  product: windows
level: high
tags:
  - attack.execution
  - attack.t1059.007
  - attack.t1027
detection:
  selection_img:
    Image|endswith:
      - '\node.exe'
      - '\node.dll'
  selection_suspicious_path:
    Image|contains:
      - '\AppData\Local\Temp\'
      - '\AppData\Roaming\'
      - '\Users\Public\'
      - '\Downloads\'
  selection_args:
    CommandLine|contains:
      - '.jsc'
      - '--snapshot-blob'
      - 'Login Data'
      - 'Local State'
      - 'wallet'
      - 'exodus'
      - 'metamask'
  condition: selection_img and (selection_suspicious_path or selection_args)
falsepositives:
  - Legitimate development tooling in temp paths (tune by parent process)
---
title: DLL Side-Loading via Canon Signed Binary (Lumma/SectopRAT Chain)
id: 6b1e4f8a-2c9d-4e7a-a5b3-1d8f0c2e4a96
status: experimental
description: Detects DLL side-loading patterns where a legitimate Canon-branded executable loads unsigned DLLs from user-writable paths, per the canon sideloading tag in the ClickFix RAT deployment pulse.
author: Security Arsenal Threat Intelligence
date: 2026/09/30
logsource:
  category: image_load
  product: windows
level: high
tags:
  - attack.defense_evasion
  - attack.t1574.002
detection:
  selection_loader:
    Image|contains: 'canon'
  selection_dll_path:
    ImageLoaded|contains:
      - '\AppData\'
      - '\Users\Public\'
      - '\Temp\'
      - '\Downloads\'
  filter_signed:
    Signed: 'true'
  condition: selection_loader and selection_dll_path and not filter_signed
falsepositives:
  - Canon utility suites loading third-party plugins (whitelist by hash)
KQL — Microsoft Sentinel / Defender
// Hunt: ClickFix execution chain + JSCeal C2 + credential store access
// Microsoft Sentinel / MDE — run over last 30 days
let ClickFix =
DeviceProcessEvents
| where TimeGenerated > ago(30d)
| where InitiatingProcessFileName in~ ("chrome.exe","msedge.exe","firefox.exe","brave.exe")
| where FileName in~ ("powershell.exe","pwsh.exe","cmd.exe","mshta.exe","rundll32.exe")
| where ProcessCommandLine has_any ("FromBase64String","Invoke-Expression"," iex ","DownloadString","Invoke-WebRequest","-enc "," -ec ","Hidden")
| project TimeGenerated, DeviceName, AccountName, FileName, ProcessCommandLine, InitiatingProcessFileName;
let JSCealC2 =
DeviceNetworkEvents
| where TimeGenerated > ago(30d)
| where RemoteUrl endswith ".info"
| where InitiatingProcessFileName in~ ("node.exe","powershell.exe","rundll32.exe")
| project TimeGenerated, DeviceName, InitiatingProcessFileName, RemoteUrl, RemoteIP;
let CredStoreAccess =
DeviceFileEvents
| where TimeGenerated > ago(30d)
| where FileName in~ ("Login Data","Local State","Cookies")
| where FolderPath has_any ("\\Google\\Chrome\\","\\Microsoft\\Edge\\","\\BraveSoftware\\")
| where InitiatingProcessFileName !in~ ("chrome.exe","msedge.exe","brave.exe","msmpeng.exe","explorer.exe")
| project TimeGenerated, DeviceName, InitiatingProcessFileName, FolderPath, FileName;
let KnownHashes = dynamic([
"22869e3326fe1de011cd500e666769027126c5c440b76837baf55139f30094e4",
"0457414c4504b70115798eee9c8384a8bf9e793461ffb2e0661a6dcc6ed4809f",
"14e3376befd4b7b52de0757b6264da294ac6b0f9e4ff51cb9bc5b19b243fe335",
"20c7befc174a61117770535e809046c75e93c71284bf1a9c6cd532f55b315f53",
"278e2f3e2f26c18666b89ef774b4af9ce954e36b2bf54a2392608619245d8c48",
"3cd1484cc5bf10e22d79784beba58a75d7b126c46efb5e1a85d6aab884447621"
]);
let HashHits =
DeviceFileEvents
| where TimeGenerated > ago(30d)
| where SHA256 in (KnownHashes)
| project TimeGenerated, DeviceName, FileName, FolderPath, SHA256, InitiatingProcessFileName;
union ClickFix, JSCealC2, CredStoreAccess, HashHits
| sort by TimeGenerated desc
PowerShell
# Security Arsenal - ClickFix / Lumma / SectopRAT / JSCeal IOC & Artifact Hunt
# Run as Administrator on suspect endpoints or deploy via RMM/Intune
$report = @()

# 1) Known payload hashes from OTX pulses
$hashes = @(
  "22869e3326fe1de011cd500e666769027126c5c440b76837baf55139f30094e4",
  "0457414c4504b70115798eee9c8384a8bf9e793461ffb2e0661a6dcc6ed4809f",
  "14e3376befd4b7b52de0757b6264da294ac6b0f9e4ff51cb9bc5b19b243fe335",
  "20c7befc174a61117770535e809046c75e93c71284bf1a9c6cd532f55b315f53",
  "278e2f3e2f26c18666b89ef774b4af9ce954e36b2bf54a2392608619245d8c48",
  "3cd1484cc5bf10e22d79784beba58a75d7b126c46efb5e1a85d6aab884447621"
)

Write-Host "[+] Scanning user-writable paths for known payload hashes..."
$scanPaths = @("$env:TEMP","$env:LOCALAPPDATA","$env:APPDATA","C:\Users\Public","$env:USERPROFILE\Downloads")
foreach ($p in $scanPaths) {
  if (Test-Path $p) {
    Get-ChildItem -Path $p -Recurse -File -ErrorAction SilentlyContinue | ForEach-Object {
      try {
        $h = (Get-FileHash -Path $_.FullName -Algorithm SHA256 -ErrorAction Stop).Hash.ToLower()
        if ($hashes -contains $h) {
          $report += "HASH HIT: $($_.FullName) [$h]"
        }
      } catch {}
    }
  }
}

# 2) Persistence artifacts - Run keys pointing to user-writable paths
Write-Host "[+] Checking Run keys for suspicious persistence..."
$runKeys = @(
  "HKCU:\Software\Microsoft\Windows\CurrentVersion\Run",
  "HKLM:\Software\Microsoft\Windows\CurrentVersion\Run"
)
foreach ($k in $runKeys) {
  if (Test-Path $k) {
    (Get-ItemProperty $k).PSObject.Properties | Where-Object {
      $_.Value -match "AppData|Public|Temp|powershell|node\.exe|mshta"
    } | ForEach-Object { $report += "PERSISTENCE: $k :: $($_.Name) = $($_.Value)" }
  }
}

# 3) Scheduled tasks referencing script interpreters in user paths
Write-Host "[+] Checking scheduled tasks for encoded/suspicious actions..."
Get-ScheduledTask | ForEach-Object {
  $action = ($_.Actions | ForEach-Object { "$($_.Execute) $($_.Arguments)" }) -join " "
  if ($action -match "powershell.*-e[nc]|mshta|AppData.*\.ps1|node\.exe") {
    $report += "TASK HIT: $($_.TaskName) :: $action"
  }
}

# 4) JSCeal C2 check - active connections to .info TLDs by node/script processes
Write-Host "[+] Checking live connections from node/script processes..."
Get-NetTCPConnection -State Established -ErrorAction SilentlyContinue | ForEach-Object {
  $proc = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
  if ($proc -and $proc.ProcessName -match "node|powershell|rundll32|mshta") {
    try {
      $dns = (Resolve-DnsName -Name $_.RemoteAddress -ErrorAction Stop -DnsOnly).NameHost
    } catch { $dns = $_.RemoteAddress }
    if ($dns -match "\.info$") {
      $report += "C2 SUSPECT: $($proc.ProcessName) (PID $($_.OwningProcess)) -> $dns : $($_.RemotePort)"
    }
  }
}

# 5) ClickFix artifact - suspicious PowerShell history containing paste-style commands
Write-Host "[+] Checking PowerShell history for ClickFix paste artifacts..."
$histPaths = Get-ChildItem "C:\Users\*\AppData\Roaming\Microsoft\Windows\PowerShell\PSReadLine\ConsoleHost_history.txt" -ErrorAction SilentlyContinue
foreach ($h in $histPaths) {
  $hits = Select-String -Path $h.FullName -Pattern "FromBase64String|Invoke-Expression|DownloadString|iex " -ErrorAction SilentlyContinue
  foreach ($hit in $hits) { $report += "CLICKFIX HISTORY: $($h.FullName) line $($hit.LineNumber): $($hit.Line.Trim())" }
}

# Output
Write-Host "`n===== HUNT RESULTS ====="
if ($report.Count -eq 0) { Write-Host "No indicators found." } else { $report | ForEach-Object { Write-Host $_ } }
$report | Out-File "$env:TEMP\secarsenal_hunt_$(Get-Date -Format yyyyMMdd_HHmm).txt"

Response Priorities

Immediate (0–4 hours)

  • Block console.info and profile.info at DNS/proxy; alert on any historical resolution (30-day lookback)
  • Load all 23 ClickFix-chain hashes and 11 JSCeal hashes into EDR block lists and SIEM TI matching
  • Deploy the ClickFix Sigma rule — browser-spawned encoded PowerShell is the single highest-signal detection for this entire campaign class
  • Enable PowerShell Script Block Logging and clipboard-monitoring telemetry if not already active (ClickFix requires the victim to paste and run)
  • Sweep endpoints with the hunt script; isolate any host with hash or C2 hits

Within 24 Hours

  • Any host with Lumma/SectopRAT/JSCeal indicators = assume full credential compromise. Force enterprise password resets from a clean device, revoke all active sessions/OAuth tokens (IdP-level), and rotate credentials stored in browsers on that host
  • Prioritize cryptocurrency wallet and exchange accounts — JSCeal specifically targets these; check for unauthorized wallet-extension access and exchange session anomalies
  • Rotate service-account and API keys stored on affected endpoints; stealers exfiltrate .env files and cloud CLI credential stores
  • SectopRAT's hidden-browser capability means session tokens may already be replayed — review IdP logs for impossible-travel and session reuse

Within 1 Week

  • Block or restrict mshta, and PowerShell child processes of browsers via WDAC/AppLocker — this breaks the ClickFix execution model outright
  • Harden Node.js: alert on node.exe executing outside approved development paths; consider an allowlist for production servers
  • User awareness push specifically on the fake CAPTCHA "paste this command" lure — show staff the exact ClickFix flow; no legitimate site ever asks users to run commands to prove humanity
  • Review Google Ads-driven browsing risk: consider conditional-access policies or browser isolation for high-risk roles (finance, crypto ops)
  • Add macOS coverage — AMOS/MacSync confirm this campaign hits Macs; ensure EDR parity and block unsigned terminal-command execution prompts
  • Subscribe to OTX pulse feeds for Lumma/JSCeal tag tracking and automate hash/domain ingestion into your TI pipeline

Related Resources

Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.