logo

ClickFix Campaign Abuses Compromised Sites to Deploy MIMICRAT Malware

ID: 72b2a44c-8bdd-5cc7-8c4f-355b4f4cac85

STIX ID: report--72b2a44c-8bdd-5cc7-8c4f-355b4f4cac85

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2026-02-20

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Researchers disclosed a sophisticated ClickFix campaign that compromises legitimate sites to deliver a custom C++ RAT called MIMICRAT (AstarionRAT). The attack uses a multi-stage PowerShell chain that bypasses ETW and AMSI, drops a Lua-scripted shellcode loader, and executes an in-memory RAT communicating over HTTPS; the implant supports token impersonation, SOCKS5 tunneling, and 22 post-exploitation commands, with suspected objectives of data exfiltration or ransomware.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.