MIMICRAT: ClickFix Campaign Delivers Custom RAT via Compromised Legitimate Websites
Feb. 20, 2026, 9:43 p.m.
Description
A sophisticated ClickFix campaign has been uncovered, compromising legitimate websites to deliver a multi-stage malware chain. The attack culminates in MIMICRAT, a custom remote access trojan with advanced capabilities. The campaign uses compromised sites across industries and geographies for delivery, employing a five-stage PowerShell chain that bypasses security measures before deploying a Lua-scripted shellcode loader. MIMICRAT, the final payload, is a native C++ RAT featuring malleable C2 profiles, Windows token theft, and SOCKS5 proxy functionality. The attack chain involves multiple compromised websites, obfuscated scripts, and sophisticated evasion techniques, demonstrating a high level of operational sophistication.
Tags
Date
- Created: Feb. 20, 2026, 2:51 p.m.
- Published: Feb. 20, 2026, 2:51 p.m.
- Modified: Feb. 20, 2026, 9:43 p.m.
Indicators
- bcc7a0e53ebc62c77b7b6e3585166bfd7164f65a8115e7c8bda568279ab4f6f1
- a4ce2eaeb144328c973e99614662a772b998faf6
- 5e0a30d8d91d5fd46da73f3e6555936233d870ac789ca7dd64c9d3cc74719f51
- a508d0bb583dc6e5f97b6094f8f910b5b6f2b9d5528c04e4dee62c343fce6f4b
- 055336daf2ac9d5bbc329fd52bb539085d00e2302fa75a0c7e9d52f540b28beb
- 45.13.212.250
- www.ndibstersoft.com
- www.investonline.in
Additional Informations
- Finance
- Education
- xmri.network
- investonline.in
- wexmri.cc
- United States of America
- China