RMMProject is a DLL-based remote access trojan delivered by the custom Potemkin loader in a ClickFix-driven intrusion reported by Huntress in May/June 2026. It was loaded reflectively in memory after Potemkin used a deterministic DGA and custom communications to locate command-and-control infrastructure; the live C2 domain observed for Potemkin/RMMProject was anus-staylard[.]xyz. The malware is described as a 4.4 MB x64, Lua-scriptable DLL embedding LuaJIT and exposing native modules for HTTP, JSON, SQLite, Windows registry access, ASN.1 parsing, and filesystem enumeration.
RMMProject reportedly implements 15 task types, including browser password and credential theft, cookie theft from Chrome, Firefox, and Edge, screenshot capture, hidden-desktop remote control, process execution, process injection, Lua script execution, and runtime module loading. It compresses stolen cookie data with zlib before exfiltration to C2. A notable capability is bypassing Chrome App-Bound Encryption: RMMProject injects an embedded helper DLL into a spawned Chrome or Edge process and uses Chrome's IElevator COM interface to decrypt protected keys. The helper DLL was reported with SHA-256 cd4e5e2c65b1660470d3446539ee68adf5faeece3eaeb46583623be9911ee145. Huntress also identified a hidden-desktop remote control component referred to as RTSC, which creates an invisible Windows desktop and launches Chrome or Edge on it for attacker interaction.
In the documented intrusion, initial access came from a ClickFix social-engineering lure on a compromised website that tricked a user into executing a malicious Run dialog command. That chain abused pcalua.exe to proxy mshta.exe, fetched an HTA from cl.distritovagas[.]com, downloaded inst24.msi from sonra.eutialyson[.]com, and installed Potemkin, which then delivered RMMProject entirely in memory. The intrusion later involved hands-on-keyboard activity, lateral movement, Defender evasion, and deployment of EtherRAT to more than 11 hosts. High-confidence indicators directly associated with RMMProject in the reporting include the C2 domain anus-staylard[.]xyz, the recovered follow-on DLL avast_update.bin with SHA-256 3b7ae925e2d64522b4f69b56285b05aeca8c5aab5ab46a9c02c4fafb69d881ce, and the helper DLL hash cd4e5e2c65b1660470d3446539ee68adf5faeece3eaeb46583623be9911ee145.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
RMMProject, a 4.4 MB DLL with 15 task types covering browser credential theft, cookie stealing across Chrome, Firefox, and Edge, a hidden remote desktop module, and process injection.
RMMProject, a 4.4 MB DLL with 15 task types covering browser credential theft, cookie stealing across Chrome, Firefox, and Edge...
For each candidate domain, Potemkin sends an HTTP GET request to a fixed URL path... EtherRAT enters an endless polling loop. Each request goes to a freshly randomized URL
That script downloaded and installed an MSI package in the background with no visible indication to the user. Separately, the attacker deployed EtherRAT... Five hours later, the attacker dropped EtherRAT and set up a Cloudflare tunnel using a renamed copy of cloudflared.
The custom "Potemkin" loader used a deterministic DGA and custom cipher to deploy RMMProject. RMMProject RAT bypassed Chrome's App-Bound Encryption and embedded a LuaJIT scripting engine. The threat actors deployed EtherRAT...
11 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remote access trojan that bypasses Chrome's App-Bound Encryption and includes an embedded LuaJIT scripting engine for post-compromise activity.
A fully featured remote access tool loaded entirely in memory by Potemkin. It supports browser credential theft, cookie theft, hidden remote desktop capability, and process injection.
A Lua-scriptable malicious DLL used for remote screen control, browser credential theft, screenshot capture, arbitrary Lua execution, browser process termination, and runtime download/execution of additional modules.
Lua-scriptable DLL module loaded by Potemkin. It steals browser passwords, cookies, credentials, and autofill data from Chrome, Firefox, and Edge; bypasses Chrome App-Bound Encryption via helper DLL injection; supports hidden-desktop remote control, screenshots, process execution, process injection, Lua task execution, and runtime module loading.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.