Hackers Use Potemkin Loader to Deliver RMMProject RAT in ClickFix Intrusion
ID: fee81168-c5f6-5eac-a519-49a2cbaa5721
STIX ID: report--fee81168-c5f6-5eac-a519-49a2cbaa5721
Feed Name: Cyber Press
## Executive summary A ClickFix campaign using social-engineered Run-dialog commands dropped the Potemkin loader which used a DGA to fetch modules and deployed RMMProject (a Lua-scriptable RAT with credential-theft and browser ABE bypass capabilities) and EtherRAT (a Node.js backdoor that retrieves C2 from an Ethereum smart contract). Operators used Cloudflare tunnels for persistence, disabled Windows Defender via PowerShell and registry changes, and moved laterally with WMIExec/SMBExec to compromise 11 hosts including the domain controller.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
