logo

ClickFix Attack Deploys Potemkin Loader, RMMProject RAT, and EtherRAT Across 11 Hosts

ID: cad01fa0-7b93-5b32-be5d-e8c235a68bb9

STIX ID: report--cad01fa0-7b93-5b32-be5d-e8c235a68bb9

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-06-17

Date Updated: 2026-06-17

Author: Mayura Kathir

...
...

A May 2026 ClickFix social-engineering campaign resulted in an 11-host intrusion chain using a Potemkin x64 loader (DGA-based), RMMProject (Lua-scriptable RAT with credential-theft and hidden-desktop remote control), and EtherRAT (blockchain-resolved C2); attackers used in-memory module loading, LOLBIN abuse, Chisel tunnels, WMIExec/SMBExec lateral movement, and per-user Run persistence—report includes IoCs and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.