Cybersecurity researchers have uncovered a new malware campaign using AI-generated websites to trick users into downloading a dangerous remote access Trojan (RAT).
Discovered by Zscaler ThreatLabz in March 2026, the campaign targets customers of a major Brazilian bank using a deceptive technique known as ClickFix.
By displaying a fake Cloudflare CAPTCHA and a simulated Blue Screen of Death (BSOD), hackers pressure victims into running malicious PowerShell commands.
The resulting infection delivers SmartRAT, a highly capable banking malware designed to steal financial data and give attackers full control over a compromised system.
Trend Micro researchers previously tracked a similar attack path, dubbing the malware Banana RAT.
Fake Cloudflare Lures SmartRAT
The attack begins when a user visits a typosquatting domain, such as cartaobb[.]com, which impersonates a legitimate Brazilian bank.
Researchers noted that the fraudulent webpage contains AI-generated code comments, suggesting that threat actors are using modern website builders to scale their operations quickly.

The site greets visitors with a fake Cloudflare CAPTCHA prompt that mimics a standard security check.
To prevent researchers from analyzing the trap, the webpage uses anti-inspection scripts that turn off developer tools and repeatedly clear the browser’s console log.
Once the user clicks the fake CAPTCHA, a malicious script immediately copies a PowerShell command to the victim’s clipboard. The browser is then forced into fullscreen mode to display a fake BSOD error message.
This screen acts as a system recovery lure, explicitly instructing the trapped user to press a specific key combination and paste the copied command into the Windows Run dialog.

The lockdown routine restricts keyboard input while temporarily allowing only the keys needed to execute this malicious flow.
If the victim falls for the trick, the executed PowerShell command retrieves a stealth dropper script from a remote server.
This dropper quietly hides its console window, downloads an encrypted payload, and executes it without raising immediate suspicion.
The final decrypted payload is SmartRAT, a sophisticated threat built entirely in PowerShell. To ensure it survives system reboots, the malware establishes persistence by creating a scheduled task or installing a Windows service with elevated system privileges.
SmartRAT is heavily focused on financial theft and monitoring. The malware actively monitors a victim’s active windows for keywords related to popular banks, credit unions, and cryptocurrency platforms such as Binance and MercadoPago.
When a target application is detected, it immediately alerts the threat actor.
The operator can then deploy full-screen fake overlays that mimic legitimate banking interfaces, tricking users into entering their passwords and sensitive data directly into the attacker’s hands, Zscaler said.
Indicators of Compromise
| Indicator | Description |
|---|---|
crefisa[.]online | Fraudulent domain |
vfsgloball[.]net | Fraudulent domain |
cartaobb.com | Fraudulent domain |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.