Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Potemkin Loader & RMMProject The Anatomy of a ClickFix Attack

0
Medium
Published: Tue Jun 16 2026 (06/16/2026, 14:27:51 UTC)
Source: AlienVault OTX General

Description

This threat describes a multi-stage malware intrusion initiated by a ClickFix social engineering attack on an unmonitored endpoint. The attack chain begins with a malicious HTA payload that installs Potemkin, a custom loader using a deterministic domain generation algorithm (DGA). Potemkin delivers RMMProject, a Lua-scriptable remote access trojan (RAT) capable of browser credential theft, hidden desktop control, and multiple task types. The attacker also deploys EtherRAT, a Node.js backdoor using Ethereum blockchain for command and control (C2) resolution, and establishes a Cloudflare tunnel for persistence. The attacker actively disables Windows Defender and uses lateral movement techniques such as WMIExec and SMBExec to spread malware and reach the domain controller.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 06/16/2026, 17:45:13 UTC

Technical Analysis

The described attack involves a social engineering vector (ClickFix) delivering a malicious HTA payload that silently installs Potemkin, a custom loader with a deterministic DGA. Potemkin subsequently delivers RMMProject, a 4.4 MB Lua-scriptable RAT with capabilities including Chrome App-Bound Encryption bypass for credential theft, hidden desktop remote control, and 15 task types. EtherRAT, a Node.js backdoor leveraging Ethereum blockchain for C2 address resolution, is also deployed. Persistence is maintained via a Cloudflare tunnel. The attacker performs hands-on-keyboard actions to disable Windows Defender through AMSI bypasses, registry edits, and service termination. Lateral movement is conducted using WMIExec and SMBExec to deploy malware across the network, ultimately compromising the domain controller.

Potential Impact

The attack results in credential theft, persistent remote access, and extensive lateral movement within the targeted network, including compromise of the domain controller. The use of advanced evasion techniques against Windows Defender and AMSI, combined with blockchain-based C2 and multi-stage payload delivery, enables sustained attacker presence and control over multiple hosts.

Mitigation Recommendations

No official patch or vendor advisory is available for this threat. Since this is a multi-stage malware attack leveraging social engineering and endpoint compromise, mitigation should focus on monitoring for suspicious HTA payloads, detecting Potemkin and RMMProject indicators, and blocking known C2 infrastructure such as Cloudflare tunnels and Ethereum blockchain-based communications. Endpoint detection and response solutions should be tuned to detect AMSI bypass attempts and lateral movement techniques like WMIExec and SMBExec. Network segmentation and restricting administrative tool usage can help limit lateral spread. Patch status is not yet confirmed — check vendor advisories for any updates.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.huntress.com/blog/potemkin-loader-rmmproject-clickfix-attack"]
Adversary
null
Pulse Id
6a315d670f9460fe003298a8
Threat Score
null

Indicators of Compromise

Domain

ValueDescriptionCopy
domainresumeacceptable.com
domaincl.distritovagas.com
domainsonra.eutialyson.com
domainpestrear-lamp.xyz
domainanus-staylard.xyz
domainfair-bath-fond.xyz
domainrule-bead-dust.xyz
domainuglyshop-mare.xyz

Hash

ValueDescriptionCopy
hash79f7b67ce8b39070f3e1c2b90fce0ce84134782a7dedcccc1edac197ee9e089b
hashd37cc44db90a65341263deb162024447
hash4537b37b65e9dc35640d750f3fa7f4944534f6b1
hash2abe5dd3a057fdef935722e50e9251c272d29fd26113187b853a1f9a9cb89d9b
hash2ada24dd6e517f37942b749c2bd57ddd97445e9853002cee70a0bc30d0b0ce3a
hash3b7ae925e2d64522b4f69b56285b05aeca8c5aab5ab46a9c02c4fafb69d881ce
hashcd4e5e2c65b1660470d3446539ee68adf5faeece3eaeb46583623be9911ee145

Url

ValueDescriptionCopy
urlhttp://sonra.eutialyson.com/inst24.msi
urlhttps://cl.distritovagas.com/hte.hta
urlhttp://77.110.122.58:23205/cons_1.0.1.msi
urlhttp://77.110.122.58:23205/lQhEQui9a4lZ.exe
urlhttp://77.110.122.58:23205/lQhEQui9a4lZ.exe'
urlhttp://77.110.122.58:44479/bjxxUmG8K3uy.ps1
urlhttps://resumeacceptable.com

Ip

ValueDescriptionCopy
ip77.110.122.58
ip213.165.41.26

Threat ID: 6a31884a0b89be6888f3d820

Added to database: 6/16/2026, 5:30:50 PM

Last enriched: 6/16/2026, 5:45:13 PM

Last updated: 6/17/2026, 4:21:25 AM

Views: 86

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses