BrowserWare is a commercially operated ClickFix-as-a-Service platform used to deliver social-engineering lures and stage follow-on malware. Reported as active in 2026, it uses a Polygon smart contract (0xd2572Aa454e6250E54C483ca89eEfe02d22e5937) to publish its current C2 panel URL, making domain-based disruption less effective. The contract owner wallet was reported as 0xcaf2c54e400437da717cf215181b170f65187abf. The lure page contained XOR-obfuscated JavaScript that resolved the C2 URL via multiple Polygon RPC endpoints; the active panel URL was buck-cdns-server.sbs, with configuration observed at /api/index.php?a=cfg. Requests were encrypted with RC4 using a base key plus an 8-byte nonce, and responses were encrypted with AES-256-GCM using a SHA-256-derived key. Observed API endpoints included /api/index.php?a=cfg, /api/index.php?a=evt, /api/index.php?a=init, /api/index.php?a=dl, and /api/index.php?a=js&mode={mode_name}. BrowserWare supports seven lure modes: browser, font, recaptcha, bsod, silent, cloudflare, and cf_update.
Observed delivery vectors included compromised websites, dedicated campaign domains, and direct IP access to 77.91.65.56. One compromised site was npimedia.com, described as a legitimate domain later hijacked through a WordPress compromise chain. A dedicated campaign domain, fontfix-chrome.com, was registered on 2026-02-18 through Tucows and fronted by Cloudflare. The lure impersonated a Chrome troubleshooting page with Google-branded styling. In browser mode, victims were instructed to paste the path \Chrome\Fonts\FontClientsCompile\ into File Explorer to trigger execution via a malicious network share or similar mechanism. The page also embedded logo.jpg, a JPEG+PE polyglot containing a valid Windows PE executable. The embedded PE had SHA-256 6054b8a3906ba0939dbd2f910289f78e58e96b86489bf0a1574a97c51a4a0774, and the full JPEG had SHA-256 54de8462597fa1a96250c13a1a01d74a135e8753d413f9d7e956a3070f58290c. The PE was an AMD64 Windows GUI executable compiled with GCC 15.1.0/15.2.0 (MinGW-w64) on 2026-02-19 19:10:53 UTC. The stager created a hidden window, used raw sockets for a custom HTTP/1.1 client, dynamically resolved APIs, and downloaded second-stage payloads disguised as images, including /logoo.png, /bgo.jpg, /headero.jpg, and /spriteo.png.
Leaked expired rental configurations showed BrowserWare operates as a multi-tenant rental platform with per-customer settings and automatic expiration. One leaked configuration from 2fa-cp.click showed mode clickfix, enabled false, rentalExpired true, and allowedOs set to windows. The leaked blockedCountries list included BY, KZ, AM, AZ, KG, MD, TJ, TM, UZ, RU, and UA, which researchers assessed as a CIS exclusion pattern consistent with a Russian-speaking operator. Infrastructure was linked to the ALTAWK/DGTLS-MNT bulletproof hosting ecosystem in Amsterdam. The lure-hosting IP 77.91.65.56 was tied to that cluster, and the C2 IP 94.154.35.227 served buck-cdns-server.sbs, 2fa-cp.click, sdn-cloudflare-js.click, and 2fa-cp.cfd. Reporting described BrowserWare as a mature, commercially operated social-engineering distribution platform resistant to traditional takedown methods.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
MITRE ATT&CK Mapping ... Resource Development T1583.001 Acquire Infrastructure: Domains fontfix-chrome.com , buck-cdns-server.sbs , expired rental domains
MITRE ATT&CK Mapping ... Resource Development T1583.003 Acquire Infrastructure: VPS DGTLS-MNT bulletproof hosting allocation
MITRE ATT&CK Mapping ... Command and Control T1071.001 Application Layer Protocol: Web HTTP API to /api/index.php endpoints
MITRE ATT&CK Mapping ... Command and Control T1102.002 Web Service: Bidirectional Communication Polygon blockchain for C2 URL resolution
The stager's behavior: ... Downloads second-stage payloads disguised as images: /logoo.png , /bgo.jpg , /headero.jpg , /spriteo.png
27 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
BrowserWare is a commercially operated ClickFix-as-a-Service platform that delivers social-engineering lures through multiple modes, resolves its C2 via a Polygon smart contract, encrypts configuration and C2 traffic, and uses a JPEG+PE polyglot stager to download second-stage payloads.
Malware/tooling referenced as part of prior ClickFix campaigns on the same infrastructure cluster.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.