Cyber Security News

New MIMICRAT Custom RAT Uncovered in Sophisticated Multi-Stage ClickFix Campaign

A sophisticated new cyber campaign has been uncovered, utilizing a deceptive technique known as “ClickFix” to distribute a custom remote access trojan dubbed MIMICRAT.

This operation compromises legitimate websites to serve as delivery vectors, bypassing traditional security controls by relying on social engineering rather than software exploits.

The malware itself is a versatile, native C++ implant designed for long-term stealth and persistence, posing a severe risk to global enterprises.

The attack sequence initiates when a user visits a trusted site, such as a financial tool, that has been silently injected with malicious JavaScript.

This script presents a fraudulent Cloudflare verification pop-up, urging the victim to copy and execute a specific PowerShell command to resolve a supposed browser error.

By exploiting user trust, this “ClickFix” tactic effectively circumvents browser-based download protections.

Elastic analysts identified this complex threat in early February 2026, observing its use of five distinct infection stages to successfully evade detection.

The researchers highlighted that the campaign targets multiple industries by dynamically localizing lures into 17 different languages, ensuring broad reach across various geographies.

bincheck.io page source showing the injected script loading jq.php from investonline.in (Source – Elastic)

They noted that the malware’s modular design allows attackers to adapt their tactics rapidly.

The final payload, MIMICRAT, is equipped with advanced capabilities, including Windows token theft, file system manipulation, and SOCKS5 tunneling.

It maintains persistence while communicating with command-and-control servers using malleable HTTP profiles that blend seamlessly with legitimate web analytics traffic.

This sophisticated camouflage makes identification by network defenders exceptionally challenging, as the malicious signals are hidden amidst normal background noise.

Stealthy Infection and Execution

The infection mechanism is engineered to bypass modern defenses through a series of calculated, obfuscated steps.

After the initial PowerShell execution, a highly obfuscated second script is downloaded to disable Windows Event Tracing and the Antimalware Scan Interface (AMSI).

This critical step blinds security tools, allowing the subsequent stages to operate on the victim’s machine without generating standard alerts.

Following these bypasses, a Lua-based loader is dropped to decrypt and execute the final shellcode entirely within system memory.

This fileless approach ensures that MIMICRAT resides only in RAM, significantly reducing its digital footprint and complicating forensic analysis for security teams attempting to trace the intrusion. The use of a custom Lua loader further obscures the attack flow.

Obfuscated powershell execution (Source – Elastic)

To defend against this threat, organizations must enhance user training to recognize fake browser verification prompts and avoid pasting unknown commands.

Security teams should enforce strict PowerShell execution policies and monitor for obfuscated command lines.

Blocking known malicious domains and inspecting network traffic for MIMICRAT’s specific communication patterns is also critical for disrupting the attack chain before data exfiltration occurs.

Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

3 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

13 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

14 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

14 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

14 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

15 hours ago