logo

MIMICRAT: ClickFix Campaign Delivers Custom RAT via Compromised Legitimate Websites

ID: 48342a2d-2922-54cf-9937-ec70f4e28738

STIX ID: report--48342a2d-2922-54cf-9937-ec70f4e28738

Feed Name: Elastic Security Labs

Threat Score
78/100

Date Published: 2026-02-20

Date Updated: 2026-04-27

...
...

Elastic Security Labs documents an active, multi-stage ClickFix campaign that compromises legitimate websites to deliver a five-stage infection chain culminating in a bespoke native C++ remote access trojan named MIMICRAT; the report details delivery via clipboard PowerShell lures, ETW and AMSI bypasses, a Lua in-memory loader and shellcode stage, extensive post-exploitation capabilities (token theft, SOCKS5 tunneling, 22 command dispatch), and associated IOCs and infrastructure including CloudFront C2 relays and multiple IPs/domains.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.