ClickFix Deno Abuse to CastleRAT

Reported 04 Jun 2026 by otx · Severity: medium

Activity began with a ClickFix-style social engineering chain that led to MSI execution, PowerShell staging, and installation/use of Deno to run attacker-controlled JavaScript. Follow-on activity downloaded a portable Python runtime, `install.pyc`, and an encrypted `.MOa` contain