Velvet Tempest deploys CastleRAT via ClickFix in Termite ransomware staging
A five-year ransomware affiliate that cycled through Ryuk, Conti, BlackCat, and RansomHub now uses ClickFix to stage Termite ransomware intrusions via CastleRAT. MalBeacon tracked 12 days of hands-on-keyboard activity in a U.S. environment.
Read more →