When Trust Becomes the Weapon: Inside the ClickFix/MIMICRAT Campaign
ID: bfb68985-4889-5a9e-b15f-80d41e487d5a
STIX ID: report--bfb68985-4889-5a9e-b15f-80d41e487d5a
Feed Name: NoHackie
Elastic Security Labs describes an active, highly sophisticated ClickFix-driven campaign (MIMICRAT) that compromises legitimate websites to trick users into pasting and executing obfuscated PowerShell commands, leading to a five-stage infection chain that disables ETW/AMSI, drops an XOR-decrypted Lua loader (zbuild.exe) and reflectively loads in-memory Meterpreter-style shellcode before deploying a custom C++ RAT (MIMICRAT) with encrypted HTTPS C2 via CloudFront and broad post-exploitation capabilities; the report includes IOCs, a YARA rule, MITRE ATT&CK mapping, and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
