MIMICRAT: ClickFix Campaign Delivers Custom RAT via Compromised Legitimate Websites

Feb. 20, 2026, 9:43 p.m.

Description

A sophisticated ClickFix campaign has been uncovered, compromising legitimate websites to deliver a multi-stage malware chain. The attack culminates in MIMICRAT, a custom remote access trojan with advanced capabilities. The campaign uses compromised sites across industries and geographies for delivery, employing a five-stage PowerShell chain that bypasses security measures before deploying a Lua-scripted shellcode loader. MIMICRAT, the final payload, is a native C++ RAT featuring malleable C2 profiles, Windows token theft, and SOCKS5 proxy functionality. The attack chain involves multiple compromised websites, obfuscated scripts, and sophisticated evasion techniques, demonstrating a high level of operational sophistication.

Date

  • Created: Feb. 20, 2026, 2:51 p.m.
  • Published: Feb. 20, 2026, 2:51 p.m.
  • Modified: Feb. 20, 2026, 9:43 p.m.

Indicators

  • bcc7a0e53ebc62c77b7b6e3585166bfd7164f65a8115e7c8bda568279ab4f6f1
  • a4ce2eaeb144328c973e99614662a772b998faf6
  • 5e0a30d8d91d5fd46da73f3e6555936233d870ac789ca7dd64c9d3cc74719f51
  • a508d0bb583dc6e5f97b6094f8f910b5b6f2b9d5528c04e4dee62c343fce6f4b
  • 055336daf2ac9d5bbc329fd52bb539085d00e2302fa75a0c7e9d52f540b28beb
  • 45.13.212.250
  • www.ndibstersoft.com
  • www.investonline.in

Additional Informations

  • Finance
  • Education
  • xmri.network
  • investonline.in
  • wexmri.cc
  • United States of America
  • China