Threat IntelligenceMay 21, 2026
🎉 New DFIR Lab is live: ClickFix → RomComRAT → Domain Compromise (Private Case #35646) Step int...
New DFIR lab simulates a 9-day espionage operation involving ClickFix, RomComRAT, and domain compromise.
Summary
A new DFIR lab simulates a nine-day espionage operation. The scenario begins with a user falling for a fake CAPTCHA, leading to the deployment of custom RomComRAT implants and ultimately a domain compromise.
Indicators of Compromise
- malware — RomComRAT
Entities
ClickFix (campaign)