♡ Follow 0
Malware
Cybersecurity researchers have identified multiple ClickFix campaigns deploying three new malware loaders: BabaDeda Loader, Lorem Ipsum Loader, and Potemkin. These campaigns use…
Apple
BabaDeda Loader
BlackCat
BlueVoyant
June 25, 2026
♡ Follow 0
Malware
Potemkin is a custom x64 loader that uses a domain generation algorithm (DGA) to find its C2 server. It reflectively loads follow-on…
DGA
EtherRAT
Huntress
Potemkin
June 25, 2026
♡ Follow 0
Malware
EtherRAT is a remote access trojan (RAT) delivered via the Potemkin loader in ClickFix campaigns. It is used alongside RMMProject for credential…
ClickFix
EtherRAT
Potemkin
RAT
June 25, 2026
♡ Follow 0
Cyber Products
Chisel is a reverse SOCKS tunnel tool used by threat actors in the Potemkin campaign for persistent access and lateral movement.
Chisel
Potemkin
reverse SOCKS tunnel
June 25, 2026
♡ Follow 0
Cyber Products
Cloudflare tunnel was set up by threat actors in the Potemkin campaign to maintain persistent access to compromised systems.
Cloudflare tunnel
persistent access
Potemkin
June 25, 2026
♡ Follow 0
Cyber Products
WMIExec is a lateral movement tool used by threat actors in the Potemkin campaign to spread across the network and reach the…
Lateral Movement
Potemkin
WMIExec
June 25, 2026
♡ Follow 0
Cyber Products
SMBExec is a lateral movement tool used by threat actors in the Potemkin campaign to propagate EtherRAT across multiple hosts.
Lateral Movement
Potemkin
SMBExec
June 25, 2026