Back to Feed
Threat IntelligenceMay 21, 2026

🎉 New DFIR Lab is live: ClickFix → RomComRAT → Domain Compromise (Private Case #35646) Step int...

New DFIR lab simulates a 9-day espionage operation involving ClickFix, RomComRAT, and domain compromise.

Summary

A new DFIR lab simulates a nine-day espionage operation. The scenario begins with a user falling for a fake CAPTCHA, leading to the deployment of custom RomComRAT implants and ultimately a domain compromise.

Indicators of Compromise

  • malware — RomComRAT

Entities

ClickFix (campaign)