PULSE NAME
59 Victims, Zero Authentication: A ClickFix Campaign Force-Installs a Chrome Extension Banking Stealer and Leaves the Entire C2 Wide Open
WHITE ANTONIO EDUARDO FREDERICO AlienVault 2026-04-14 Modified: 2026-04-14
19
IOCs
MEDIUM VOLUME
A Brazilian banking fraud operation leveraging ClickFix social engineering was discovered through a community tip, exposing a completely unauthenticated command-and-control infrastructure. The campaign deploys a malicious Chrome extension masquerading as a Banco Central do Brasil tool, force-installed via Chrome Cloud Management enrollment tokens. The extension achieves zero antivirus detections while targeting eight Brazilian financial institutions. At investigation time, 59 machines were compromised with seven active connections. The operator's C2 server exposed all endpoints without authentication, including admin panels, live victim screenshots, stolen credentials in cleartext, and intercepted Pix payment data. Attribution was established through WHOIS records revealing the operator's real name, CPF, and email address. The operation specifically targeted Northern Brazilian regional banks and credit cooperatives, with evidence of compromising a school fund account.
Indicators of Compromise (19)
All IPv4 FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
IPv4 144.126.140.33 2026-04-14
FileHash-MD5 386d4093f70219b8291d3f9e6f71ee1f 2026-04-14
FileHash-SHA1 bdac75f0e71a6e2ee2030259ad5ff7c002ebc98d 2026-04-14
FileHash-SHA256 401c125517b1f845289bf0a7a33e5db0391034f631eab85dd65b76b7fec9a959 2026-04-14
FileHash-SHA256 b68eefb10e2c304681532bc0c812c7905888e6b8e47448f1e4bc1edfe7ac193d 2026-04-14
URL http://144.126.140.33:3000 2026-04-14
URL http://144.126.140.33:3000/admin 2026-04-14
URL http://144.126.140.33:3000/api/users 2026-04-14
URL http://144.126.140.33:3000/openapi.json 2026-04-14
URL http://144.126.140.33:5000 2026-04-14
URL http://protocolovirtual.org 2026-04-14
URL http://test1.amanur.com 2026-04-14
URL http://xpie348.online/instalador/get_token.ps1 2026-04-14
URL http://xpie348.online/instalador/update.xml 2026-04-14
domain amanur.com 2026-04-14
domain certificadosuporte.com.br 2026-04-14
domain protocolovirtual.org 2026-04-14
domain xpie348.online 2026-04-14
hostname test1.amanur.com 2026-04-14