MIMICRAT, also known as AstarionRAT, is a custom native x64 C++ remote-access trojan targeting Windows systems. It has been delivered through ClickFix social-engineering campaigns hosted on compromised legitimate websites. Victims are shown a localized fake Cloudflare verification prompt that instructs them to paste and execute an obfuscated PowerShell command, initiating a multistage, memory-resident infection chain. The chain bypasses PowerShell ETW logging and AMSI, uses a Lua-based loader to decrypt and execute shellcode in memory, and reflectively loads the final implant.
MIMICRAT uses encrypted HTTPS command-and-control communications with configurable HTTP profiles intended to resemble web analytics traffic. Its command set supports file-system and process operations, interactive command-shell access, Windows token theft and impersonation, reflective shellcode injection, and SOCKS5 proxy tunneling. The campaign has shown opportunistic, multilingual targeting across geographies. Public reporting has identified tactical and infrastructure overlaps with ClickFix operations that use the Matanbuchus 3.0 loader, but no definitive threat-actor attribution has been established. Likely operator objectives include follow-on ransomware deployment or data exfiltration, although these objectives have not been confirmed for MIMICRAT operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
Scheduled Task/Job is listed in the report's MITRE ATT&CK techniques.
The clipboard-delivered command is a compact and obfuscated PowerShell one-liner; it downloads a second-stage PowerShell script.
Command 78 opens a persistent interactive CMD shell over a pipe.
The command uses string slicing and arithmetic index operations on a single seed string to reconstruct both the target domain and invocation mechanism at runtime.
“token impersonation… Windows token theft… Cmd 31 Steal token… Cmd 28 Revert impersonation… Cmd 12 Spawn process… using a stolen token if available”
14 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
C++ remote access trojan delivered through ClickFix social-engineering style campaigns to establish remote control of victim machines.
Custom remote access trojan delivered via a ClickFix campaign using compromised legitimate websites (per the article title).
Custom remote access trojan delivered via ClickFix technique from compromised legitimate websites; described as mimicking C2 frameworks.
Custom C++ remote access trojan delivered via a multi-stage PowerShell chain (including ETW/AMSI bypass) and a Lua-based in-memory shellcode loader; communicates with C2 over HTTPS (port 443) using web-analytics-like HTTP profiles; supports token impersonation, interactive shell, process/file control, shellcode injection, and SOCKS5 tunneling.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.