logo

When Trust Becomes the Weapon: Inside the ClickFix/MIMICRAT Campaign

ID: bfb68985-4889-5a9e-b15f-80d41e487d5a

STIX ID: report--bfb68985-4889-5a9e-b15f-80d41e487d5a

Feed Name: NoHackie

Threat Score
92/100

Date Published: 2026-02-27

Date Updated: 2026-04-19

...
...

Elastic Security Labs describes an active, highly sophisticated ClickFix-driven campaign (MIMICRAT) that compromises legitimate websites to trick users into pasting and executing obfuscated PowerShell commands, leading to a five-stage infection chain that disables ETW/AMSI, drops an XOR-decrypted Lua loader (zbuild.exe) and reflectively loads in-memory Meterpreter-style shellcode before deploying a custom C++ RAT (MIMICRAT) with encrypted HTTPS C2 via CloudFront and broad post-exploitation capabilities; the report includes IOCs, a YARA rule, MITRE ATT&CK mapping, and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.