ClickFix Attack Deploys Potemkin Loader, RMMProject RAT, and EtherRAT Across 11 Hosts
ID: cad01fa0-7b93-5b32-be5d-e8c235a68bb9
STIX ID: report--cad01fa0-7b93-5b32-be5d-e8c235a68bb9
Feed Name: GBHackers
Threat Score
A May 2026 ClickFix social-engineering campaign resulted in an 11-host intrusion chain using a Potemkin x64 loader (DGA-based), RMMProject (Lua-scriptable RAT with credential-theft and hidden-desktop remote control), and EtherRAT (blockchain-resolved C2); attackers used in-memory module loading, LOLBIN abuse, Chisel tunnels, WMIExec/SMBExec lateral movement, and per-user Run persistence—report includes IoCs and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
