ClickFix compromised-site MIMICRAT campaign
Campaign
Summary
Hide ▲
Show ▼
The ClickFix campaign is abusing compromised legitimate sites to deliver the MIMICRAT remote access trojan through a multi-stage infection chain, widening risk across multiple industries, geographies, and 17 languages. The lure begins with a fake Cloudflare verification page and a copy-paste prompt that drives PowerShell execution, ETW/AMSI bypass, and a Lua-based loader. The operation matters because the implant supports token manipulation, SOCKS5 tunneling, and other post-exploitation actions that can enable ransomware deployment or data exfiltration.
Related Happenings
Secret Blizzard Kazuar modular P2P botnet
Malware Activity
H score28
First: 16.05.2026 17:15
Last: 16.05.2026 17:15
Sources 1
About this happening:
Kazuar is being used in a multi-stage campaign in Ukraine that ESET says likely involves Gamaredon providing access and Turla/Secret Blizzard delivering the ba...
Secret Blizzard Kazuar modular P2P botnet
Malware ActivityAbout this happening: Kazuar is being used in a multi-stage campaign in Ukraine that ESET says likely involves Gamaredon providing access and Turla/Secret Blizzard delivering the ba...
Hive0163 extortion and ransomware campaign using ClickFix and malvertising
Campaign
H score35
First: 12.03.2026 19:02
Last: 12.03.2026 19:02
Sources 1
About this happening:
Hive0163 is running an active extortion and ransomware campaign that expands access and raises the risk of large-scale data exfiltration. The operation uses ClickFix,...
Hive0163 extortion and ransomware campaign using ClickFix and malvertising
CampaignAbout this happening: Hive0163 is running an active extortion and ransomware campaign that expands access and raises the risk of large-scale data exfiltration. The operation uses ClickFix,...
Compromised legitimate WordPress websites used to infect visitors with infostealer malware campaign expands across multiple victims
Campaign
H score34
First: 11.03.2026 16:45
Last: 11.03.2026 16:45
Sources 1
About this happening:
A global ClickFix campaign is abusing compromised WordPress sites to push infostealer malware to visitors, putting credentials and financial data at risk. The operatio...
Compromised legitimate WordPress websites used to infect visitors with infostealer malware campaign expands across multiple victims
CampaignAbout this happening: A global ClickFix campaign is abusing compromised WordPress sites to push infostealer malware to visitors, putting credentials and financial data at risk. The operatio...
OAuth-phished ZIP/LNK/PowerShell malware delivery chain
Malware Activity
H score19
First: 03.03.2026 11:20
Last: 03.03.2026 11:20
Sources 1
About this happening:
ZIP-delivered malware now uses a PowerShell and DLL side-loading chain to infect Windows devices and reach an external C2 server, increasing the risk of follow-on...
OAuth-phished ZIP/LNK/PowerShell malware delivery chain
Malware ActivityAbout this happening: ZIP-delivered malware now uses a PowerShell and DLL side-loading chain to infect Windows devices and reach an external C2 server, increasing the risk of follow-on...
UAT-10027 U.S. education and healthcare targeting campaign
Campaign
H score34
First: 26.02.2026 17:17
Last: 26.02.2026 17:17
Sources 1
About this happening:
UAT-10027 is running an active campaign against U.S. education and healthcare organizations, and the activity matters because it delivers a new backdoor and supporting...
UAT-10027 U.S. education and healthcare targeting campaign
CampaignAbout this happening: UAT-10027 is running an active campaign against U.S. education and healthcare organizations, and the activity matters because it delivers a new backdoor and supporting...
Timeline
-
20.02.2026 13:55 2 articles · 4mo ago
ClickFix MIMICRAT campaign disclosed
Initial DisclosureA ClickFix campaign abuses compromised legitimate sites to deliver the MIMICRAT (aka AstarionRAT) remote access trojan. The infection chain starts at bincheck[.]io, uses a fake Cloudflare verification page and a Windows Run dialog copy-paste lure, then runs PowerShell, bypasses ETW and AMSI, and drops a Lua-based loader that executes shellcode to deploy the implant. Victims span multiple geographies, including a USA-based university and Chinese-speaking users, and the lure content is localized across 17 languages.
Show sources
- ClickFix Campaign Abuses Compromised Sites to Deploy MIMICRAT RAT — thehackernews.com — 20.02.2026 13:55
- ClickFix Campaign Abuses Compromised Sites to Deploy MIMICRAT RAT — thehackernews.com — 20.02.2026 13:55