New MIMICRAT Custom RAT Uncovered in Sophisticated Multi-Stage ClickFix Campaign
A recently identified cyber campaign employs a technique known as "ClickFix" to distribute a custom remote access trojan called MIMICRAT.
A recently identified cyber campaign employs a technique known as "ClickFix" to distribute a custom remote access trojan called MIMICRAT.
This campaign leverages legitimate websites as distribution platforms, utilizing social engineering to bypass conventional security mechanisms. The malware, developed in C++, is designed for long-term stealth and persistence, posing significant risks to global enterprises.
The attack begins when a user accesses a trusted site that has been compromised with malicious JavaScript. This script displays a fake Cloudflare verification pop-up, prompting the user to execute a PowerShell command to resolve a supposed browser error. This method bypasses browser download protections by exploiting user trust.
Elastic analysts identified this threat in early February 2026, noting its five-stage infection process designed to evade detection. The campaign targets multiple industries, adapting lures into 17 languages to maximize its reach. The modular design of the malware allows rapid adaptation of tactics.
A recently identified cyber campaign employs a technique known as "ClickFix" to distribute a custom remote access trojan called MIMICRAT.
Final payload MIMICRAT includes Windows token theft, file system manipulation, and SOCKS5 tunneling capabilities. Communicates with command-and-control servers using malleable HTTP profiles. Employs a fileless approach, existing only in RAM to reduce its digital footprint.
The infection process involves executing a highly obfuscated PowerShell script to disable Windows Event Tracing and the Antimalware Scan Interface (AMSI), allowing subsequent actions to proceed undetected. A Lua-based loader decrypts and executes the final shellcode within system memory.
Organizations should enhance user training to recognize fake verification prompts and avoid executing unknown commands. Security teams must enforce strict PowerShell execution policies and monitor for obfuscated command lines. Blocking known malicious domains and analyzing network traffic for specific communication patterns of MIMICRAT is essential to disrupt the attack chain.
Based on reporting by Cyber Security News.
