
Trojanized Zoom/Webex Installers Spread Starland RAT
Cisco Talos reports a real, ongoing campaign where a Russian-speaking criminal group tricks people into installing trojanized versions of popular software…
Attackers used fake Steam forum replies that looked like helpful troubleshooting steps for real gaming/PC problems. The posts tricked users into running PowerShell as an administrator, which then downloaded and installed the XMRig crypto miner and set it to run automatically at startup. The campaign used a newly registered domain (msfconfig[.]icu) to host the payload.
This campaign relied on newly created Steam accounts posing as helpful community members. These accounts replied to real forum threads where users were asking for help with crashes, missing items, or other common gaming and PC issues. Instead of pointing to Valve's official support, the replies told users to open PowerShell as Administrator and paste in a specific command, a technique known as ClickFix.
Once executed, the script displayed itself as a Windows optimization tool, complete with fake progress messages and delays for tasks like temporary file cleanup, DNS cache flushing, and disk checks. Behind that fake interface, the script created a directory at C:\Windows\Background, added it to Microsoft Defender exclusions, and downloaded a payload disguised as system.txt from msfconfig[.]icu over HTTPS. The payload was the XMRig cryptocurrency miner, and the script set up a scheduled task to keep it running automatically at startup.
The attack worked because it inserted itself into a moment when users were already looking for help and were primed to follow instructions. A few factors made it convincing:
Security teams and end users can look for a specific set of indicators tied to this campaign:
Any request to paste and run PowerShell or Command Prompt commands from an untrusted forum post, especially one requiring administrator privileges, should be treated as a red flag.
Organizations can reduce risk from this style of attack by reinforcing a few habits. Users should never execute PowerShell or Command Prompt commands from online forums unless the source can be trusted, and any troubleshooting request tied to admin rights or security setting changes, such as Defender exclusions, should be escalated rather than followed. If indicators of compromise are found, affected systems should be isolated from the network immediately, scanned fully with antivirus or EDR tooling, and any scheduled tasks, exclusions, or related files removed manually as part of remediation.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
A ClickFix attack instructs users to open PowerShell, Command Prompt, or the Windows Run dialog and directly enter or paste a specific command, disguising malicious activity as a helpful fix.
Attackers used newly created Steam accounts to reply to users asking for help with crashes, missing items, and other tech issues, posting fake troubleshooting steps that led to running PowerShell as administrator.
A script that appeared to be a Windows optimization tool ran fake progress messages, then downloaded an executable disguised as a text file, added a Microsoft Defender exclusion, and set persistence through a scheduled task to install an XMRig cryptocurrency miner.
Defenders can look for a C:\Windows\Background directory, Microsoft Defender exclusions, scheduled tasks beginning with XMRig-, and network traffic to msfconfig[.]icu, then isolate the system and run a full antivirus or EDR scan if found.
You post on Steam about game crashes, and a “helpful” reply says: open PowerShell as Administrator and paste this fix. That’s a ClickFix attack. You run the command, a fake Windows optimization script shows progress bars, but behind the scenes it creates C:\Windows\Background, disables Defender there, and pulls an XMRig miner from msfconfig.icu. Aha moment: real fixes almost never need random forum commands run as admin. If you already did this, check for a C:\Windows\Background folder, scheduled tasks starting with XMRig-, or any traffic to msfconfig.icu. Your move: if any fix tells you to copy PowerShell commands as admin or change Defender settings, stop and send it to security before you run a single line.

Cisco Talos reports a real, ongoing campaign where a Russian-speaking criminal group tricks people into installing trojanized versions of popular software…

Kaspersky reports an active malware campaign (“OkoBot”) that tricks people into running malicious scripts via a ClickFix-style prompt or by downloading a fake…

AI firm ORO says a suspected North Korean attacker hijacked a real conference contact’s Telegram account and lured an employee into joining a fake Microsoft…

CERT-UA reports a Sandworm-linked group (UAC-0145) is using fake CAPTCHA checks on compromised websites to persuade Ukrainian visitors to run PowerShell…

North Korea–linked actors used fake developer job offers inside a Slack community to trick targets into running a “coding assessment” project. The repository…

North Korea-linked BlueNoroff is using fake Zoom and Microsoft Teams meeting pages shared from hijacked trusted contacts (often via Telegram) to trick victims…