Potemkin Loader & RMMProject The Anatomy of a ClickFix Attack

June 16, 2026, 5:19 p.m.

Description

A ClickFix social engineering attack on an unmonitored endpoint led to a multi-stage intrusion affecting over 11 hosts. The infection chain began with a malicious HTA payload that silently installed an MSI package containing Potemkin, a custom loader with a deterministic DGA. Potemkin delivered RMMProject, a 4.4 MB Lua-scriptable RAT featuring browser credential theft with Chrome App-Bound Encryption bypass, hidden-desktop remote control, and 15 distinct task types. The attacker deployed EtherRAT, a Node.js backdoor resolving C2 addresses from Ethereum blockchain, and established a Cloudflare tunnel for persistent access. Hands-on-keyboard activity included battling Windows Defender through AMSI patches, registry modifications, and service termination, followed by lateral movement via WMIExec and SMBExec to deploy malware across the network and reach the domain controller.

Date

  • Created: June 16, 2026, 2:27 p.m.
  • Published: June 16, 2026, 2:27 p.m.
  • Modified: June 16, 2026, 5:19 p.m.

Indicators

  • 3b7ae925e2d64522b4f69b56285b05aeca8c5aab5ab46a9c02c4fafb69d881ce
  • 2ada24dd6e517f37942b749c2bd57ddd97445e9853002cee70a0bc30d0b0ce3a
  • 2abe5dd3a057fdef935722e50e9251c272d29fd26113187b853a1f9a9cb89d9b
  • cd4e5e2c65b1660470d3446539ee68adf5faeece3eaeb46583623be9911ee145
  • 79f7b67ce8b39070f3e1c2b90fce0ce84134782a7dedcccc1edac197ee9e089b
  • 77.110.122.58
  • 213.165.41.26
  • http://77.110.122.58:23205/cons_1.0.1.msi
  • https://cl.distritovagas.com/hte.hta
  • http://77.110.122.58:23205/lQhEQui9a4lZ.exe
  • http://77.110.122.58:44479/bjxxUmG8K3uy.ps1
  • http://77.110.122.58:23205/lQhEQui9a4lZ.exe'
  • https://resumeacceptable.com
  • http://sonra.eutialyson.com/inst24.msi

Additional Informations

  • cl.distritovagas.com
  • resumeacceptable.com
  • sonra.eutialyson.com
  • rule-bead-dust.xyz
  • anus-staylard.xyz
  • fair-bath-fond.xyz
  • uglyshop-mare.xyz
  • pestrear-lamp.xyz