Researchers uncovered CLICKSMOKE, a live malware-as-a-service platform hosted on dakatawebstick[.]com that delivers a Deno-based JavaScript implant through ClickFix social-engineering lures and later through an MSI installer chain. Analysis of the payload found a hardcoded JWT bearer token that exposed internal build metadata, including the operator alias "Smokest", a build note tied to PowerShell delivery, tenant identifiers, and evidence of a shared backend used to generate malware builds. The implant was designed for Windows and supports host fingerprinting, localhost mutexing, persistence through Registry Run keys and scheduled tasks, hidden PowerShell execution, command-and-control session management, and modular payload execution with Deno.

TTPs, infrastructure, and targeting history in one profile.
5 events from the most recent confirmed update back to the earliest known activity.
A follow-up investigation found the CLICKSMOKE platform remained active after earlier exposure and had rotated exposed build IDs rather than shutting down. Researchers identified a second tenant, "aero," plus an MSI-based delivery chain that installed Scoop and Deno before deploying a browser-credential stealer, further confirming a multi-tenant MaaS operation.
Breakglass Intelligence confirmed that dakatawebstick[.]com was hosting a live ClickFix malware delivery and C2 platform using a Deno-based JavaScript implant with zero VirusTotal detections at the time. Analysis documented Windows infection features including persistence, host fingerprinting, mutexing, and modular payload execution.
The dakatawebstick[.]com infrastructure was publicly reported or flagged, prompting deeper researcher investigation into the live malware platform. This marked the first public reporting referenced in the analysis.
A hardcoded JWT embedded in the Deno implant was issued, exposing build metadata for a ClickFix/PowerShell delivery build labeled "BatClickFixPS1NewV1" and linking the platform to operator alias "Smokest." The token indicated a multi-tenant malware-as-a-service backend was already in use.
The domain dakatawebstick[.]com, later identified as the CLICKSMOKE malware delivery and command-and-control platform, was newly registered. Researchers assessed this as the start of infrastructure provisioning for the operation.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 25 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
intel.breakglass.tech
Open sourceintel.breakglass.tech
Open sourceintel.breakglass.tech
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.