HomeSecurityVelvet Tempest: Distribution of DonutLoader and CastleRAT via ClickFix techniques

Velvet Tempest: Distribution of DonutLoader and CastleRAT via ClickFix techniques

A highly sophisticated campaign has come to light as security researchers have revealed the methods used by the Velvet Tempest to deploy malware on corporate networks. The threat leverages a combination of social engineering techniques, legitimate Windows tools , and advanced malware loaders, creating a particularly dangerous attack chain.

Velvet Tempest CastleRAT

The analysis, conducted by cybersecurity firm MalBeacon, tracked attacker behavior in a simulated organization environment over a period of twelve days. The research offers a rare glimpse into the real-world tactics used by modern ransomware groups during an attack.

The Velvet Tempest group and its past

The Velvet Tempest group , also known as DEV-0504 , is one of the most experienced ransomware-as-a-service actors . It has been involved in large-scale attacks for at least five years, working with various cybercriminal networks.

See also: The Evolution of Ransomware in 2026: Techniques and Organizational Protection

Researchers link its activity to some of the most destructive ransomware families of the past decade, including Ryuk, REvil, Conti, BlackMatter, BlackCat/ALPHV, LockBit and RansomHub. These malware have caused significant damage to businesses, government organizations , and critical infrastructure worldwide, making Velvet Tempest a particularly dangerous threat actor.

The research in a simulated corporate environment

The attack was monitored between February 3 and 16 in an environment that mimicked the infrastructure of a large non-profit organization in the United States. The environment included more than 3,000 endpoints and approximately 2,500 users, providing a realistic field of view for observing attacker activity.

After gaining access to the network, the attackers performed a series of reconnaissance. Among other things, they mapped Active Directory, located available computers on the network, and gathered information about the overall system structure. At the same time, a PowerShell to extract stored credentials from the Google Chrome, a practice that allows attackers to gain additional access to corporate accounts.

Velvet Tempest: Distribution of DonutLoader and CastleRAT via ClickFix techniques

The ClickFix technique and the initial intrusion

The initial breach appears to have started through a malvertisingthat leveraged the ClickFix, a social engineering method that has become increasingly common in ransomware attacks. Victims were directed to pages that combined CAPTCHA-style verification with instructions urging them to paste a seemingly innocent command into the Windows “Run” window.

See also: InstallFix: Infostealer distribution via fake installation guides by Claude Code

This command triggered execution chains via cmd.exe and leveraged the finger.exe to retrieve the first malware loaders. In some cases, the malicious content was disguised as a PDF file, but in reality it was a compressed file containing the initial payload.

Development of malicious software on the system

In the next stages of the attack, the attackers used PowerShell to download additional files and execute commands that activated further modules. Part of the process involved compiling .NET via the csc.exe, which were stored in temporary system folders.

At the same time, Python- based components were installed in the C:\ProgramData directory , allowing attackers to maintain a persistent presence on the network even after systems are rebooted .

The operation resulted in the installation of DonutLoader, a loader used to execute additional payloads, as well as the CastleRAT. The latter is a remote access trojan that is linked to the CastleLoader, known for distributing data-stealing tools such as LummaStealer.

High‑profile targets and the absence of ransomware

While the attack appeared to follow a classic ransomware pattern, researchers note that the Termite during the attack. The malware has previously targeted high-profile organizations, including SaaS company Blue Yonder and Australian IVF Genea.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: Microsoft: New ClickFix campaign distributes Lumma Stealer

Velvet Tempest: Distribution of DonutLoader and CastleRAT via ClickFix techniques

The rise of the ClickFix technique

The ClickFix technique seems to be gaining traction among ransomware groups, as it allows attackers to bypass traditional security filters and directly exploit human behavior. Researchers at Sekoia had already pointed out in April 2025 that the Interlock used similar social engineering methods to infiltrate corporate networks.

The increasing use of such techniques underscores that cybersecurity does not depend solely on technological tools, but also on user education. As attacks become increasingly sophisticated, employee awareness and the adoption of strong security policies remain critical factors for protecting organizations from modern digital threats.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS