logo

Hackers Use Potemkin Loader to Deliver RMMProject RAT in ClickFix Intrusion

ID: fee81168-c5f6-5eac-a519-49a2cbaa5721

STIX ID: report--fee81168-c5f6-5eac-a519-49a2cbaa5721

Feed Name: Cyber Press

Threat Score
78/100

Date Published: 2026-06-17

Date Updated: 2026-06-17

Author: Varshini

...
...

## Executive summary A ClickFix campaign using social-engineered Run-dialog commands dropped the Potemkin loader which used a DGA to fetch modules and deployed RMMProject (a Lua-scriptable RAT with credential-theft and browser ABE bypass capabilities) and EtherRAT (a Node.js backdoor that retrieves C2 from an Ethereum smart contract). Operators used Cloudflare tunnels for persistence, disabled Windows Defender via PowerShell and registry changes, and moved laterally with WMIExec/SMBExec to compromise 11 hosts including the domain controller.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.