Potemkin Loader & RMMProject The Anatomy of a ClickFix Attack
This threat describes a multi-stage malware intrusion initiated by a ClickFix social engineering attack on an unmonitored endpoint. The attack chain begins with a malicious HTA payload that installs Potemkin, a custom loader using a deterministic domain generation algorithm (DGA). Potemkin delivers RMMProject, a Lua-scriptable remote access trojan (RAT) capable of browser credential theft, hidden desktop control, and multiple task types. The attacker also deploys EtherRAT, a Node.js backdoor using Ethereum blockchain for command and control (C2) resolution, and establishes a Cloudflare tunnel for persistence. The attacker actively disables Windows Defender and uses lateral movement techniques such as WMIExec and SMBExec to spread malware and reach the domain controller.
AI Analysis
Technical Summary
The described attack involves a social engineering vector (ClickFix) delivering a malicious HTA payload that silently installs Potemkin, a custom loader with a deterministic DGA. Potemkin subsequently delivers RMMProject, a 4.4 MB Lua-scriptable RAT with capabilities including Chrome App-Bound Encryption bypass for credential theft, hidden desktop remote control, and 15 task types. EtherRAT, a Node.js backdoor leveraging Ethereum blockchain for C2 address resolution, is also deployed. Persistence is maintained via a Cloudflare tunnel. The attacker performs hands-on-keyboard actions to disable Windows Defender through AMSI bypasses, registry edits, and service termination. Lateral movement is conducted using WMIExec and SMBExec to deploy malware across the network, ultimately compromising the domain controller.
Potential Impact
The attack results in credential theft, persistent remote access, and extensive lateral movement within the targeted network, including compromise of the domain controller. The use of advanced evasion techniques against Windows Defender and AMSI, combined with blockchain-based C2 and multi-stage payload delivery, enables sustained attacker presence and control over multiple hosts.
Mitigation Recommendations
No official patch or vendor advisory is available for this threat. Since this is a multi-stage malware attack leveraging social engineering and endpoint compromise, mitigation should focus on monitoring for suspicious HTA payloads, detecting Potemkin and RMMProject indicators, and blocking known C2 infrastructure such as Cloudflare tunnels and Ethereum blockchain-based communications. Endpoint detection and response solutions should be tuned to detect AMSI bypass attempts and lateral movement techniques like WMIExec and SMBExec. Network segmentation and restricting administrative tool usage can help limit lateral spread. Patch status is not yet confirmed — check vendor advisories for any updates.
Indicators of Compromise
- domain: resumeacceptable.com
- hash: 79f7b67ce8b39070f3e1c2b90fce0ce84134782a7dedcccc1edac197ee9e089b
- url: http://sonra.eutialyson.com/inst24.msi
- domain: cl.distritovagas.com
- domain: sonra.eutialyson.com
- url: https://cl.distritovagas.com/hte.hta
- ip: 77.110.122.58
- domain: pestrear-lamp.xyz
- hash: d37cc44db90a65341263deb162024447
- hash: 4537b37b65e9dc35640d750f3fa7f4944534f6b1
- hash: 2abe5dd3a057fdef935722e50e9251c272d29fd26113187b853a1f9a9cb89d9b
- hash: 2ada24dd6e517f37942b749c2bd57ddd97445e9853002cee70a0bc30d0b0ce3a
- hash: 3b7ae925e2d64522b4f69b56285b05aeca8c5aab5ab46a9c02c4fafb69d881ce
- hash: cd4e5e2c65b1660470d3446539ee68adf5faeece3eaeb46583623be9911ee145
- ip: 213.165.41.26
- url: http://77.110.122.58:23205/cons_1.0.1.msi
- url: http://77.110.122.58:23205/lQhEQui9a4lZ.exe
- url: http://77.110.122.58:23205/lQhEQui9a4lZ.exe'
- url: http://77.110.122.58:44479/bjxxUmG8K3uy.ps1
- url: https://resumeacceptable.com
- domain: anus-staylard.xyz
- domain: fair-bath-fond.xyz
- domain: rule-bead-dust.xyz
- domain: uglyshop-mare.xyz
Potemkin Loader & RMMProject The Anatomy of a ClickFix Attack
Description
This threat describes a multi-stage malware intrusion initiated by a ClickFix social engineering attack on an unmonitored endpoint. The attack chain begins with a malicious HTA payload that installs Potemkin, a custom loader using a deterministic domain generation algorithm (DGA). Potemkin delivers RMMProject, a Lua-scriptable remote access trojan (RAT) capable of browser credential theft, hidden desktop control, and multiple task types. The attacker also deploys EtherRAT, a Node.js backdoor using Ethereum blockchain for command and control (C2) resolution, and establishes a Cloudflare tunnel for persistence. The attacker actively disables Windows Defender and uses lateral movement techniques such as WMIExec and SMBExec to spread malware and reach the domain controller.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The described attack involves a social engineering vector (ClickFix) delivering a malicious HTA payload that silently installs Potemkin, a custom loader with a deterministic DGA. Potemkin subsequently delivers RMMProject, a 4.4 MB Lua-scriptable RAT with capabilities including Chrome App-Bound Encryption bypass for credential theft, hidden desktop remote control, and 15 task types. EtherRAT, a Node.js backdoor leveraging Ethereum blockchain for C2 address resolution, is also deployed. Persistence is maintained via a Cloudflare tunnel. The attacker performs hands-on-keyboard actions to disable Windows Defender through AMSI bypasses, registry edits, and service termination. Lateral movement is conducted using WMIExec and SMBExec to deploy malware across the network, ultimately compromising the domain controller.
Potential Impact
The attack results in credential theft, persistent remote access, and extensive lateral movement within the targeted network, including compromise of the domain controller. The use of advanced evasion techniques against Windows Defender and AMSI, combined with blockchain-based C2 and multi-stage payload delivery, enables sustained attacker presence and control over multiple hosts.
Mitigation Recommendations
No official patch or vendor advisory is available for this threat. Since this is a multi-stage malware attack leveraging social engineering and endpoint compromise, mitigation should focus on monitoring for suspicious HTA payloads, detecting Potemkin and RMMProject indicators, and blocking known C2 infrastructure such as Cloudflare tunnels and Ethereum blockchain-based communications. Endpoint detection and response solutions should be tuned to detect AMSI bypass attempts and lateral movement techniques like WMIExec and SMBExec. Network segmentation and restricting administrative tool usage can help limit lateral spread. Patch status is not yet confirmed — check vendor advisories for any updates.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.huntress.com/blog/potemkin-loader-rmmproject-clickfix-attack"]
- Adversary
- null
- Pulse Id
- 6a315d670f9460fe003298a8
- Threat Score
- null
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domainresumeacceptable.com | — | |
domaincl.distritovagas.com | — | |
domainsonra.eutialyson.com | — | |
domainpestrear-lamp.xyz | — | |
domainanus-staylard.xyz | — | |
domainfair-bath-fond.xyz | — | |
domainrule-bead-dust.xyz | — | |
domainuglyshop-mare.xyz | — |
Hash
| Value | Description | Copy |
|---|---|---|
hash79f7b67ce8b39070f3e1c2b90fce0ce84134782a7dedcccc1edac197ee9e089b | — | |
hashd37cc44db90a65341263deb162024447 | — | |
hash4537b37b65e9dc35640d750f3fa7f4944534f6b1 | — | |
hash2abe5dd3a057fdef935722e50e9251c272d29fd26113187b853a1f9a9cb89d9b | — | |
hash2ada24dd6e517f37942b749c2bd57ddd97445e9853002cee70a0bc30d0b0ce3a | — | |
hash3b7ae925e2d64522b4f69b56285b05aeca8c5aab5ab46a9c02c4fafb69d881ce | — | |
hashcd4e5e2c65b1660470d3446539ee68adf5faeece3eaeb46583623be9911ee145 | — |
Url
| Value | Description | Copy |
|---|---|---|
urlhttp://sonra.eutialyson.com/inst24.msi | — | |
urlhttps://cl.distritovagas.com/hte.hta | — | |
urlhttp://77.110.122.58:23205/cons_1.0.1.msi | — | |
urlhttp://77.110.122.58:23205/lQhEQui9a4lZ.exe | — | |
urlhttp://77.110.122.58:23205/lQhEQui9a4lZ.exe' | — | |
urlhttp://77.110.122.58:44479/bjxxUmG8K3uy.ps1 | — | |
urlhttps://resumeacceptable.com | — |
Ip
| Value | Description | Copy |
|---|---|---|
ip77.110.122.58 | — | |
ip213.165.41.26 | — |
Threat ID: 6a31884a0b89be6888f3d820
Added to database: 6/16/2026, 5:30:50 PM
Last enriched: 6/16/2026, 5:45:13 PM
Last updated: 6/17/2026, 4:21:25 AM
Views: 86
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.