ModeloRAT Malware — Analysis, Campaigns & Threat Activity

Threat entity extracted from intelligence sources

Frequency
17
occurrences
First Seen
January 19, 2026
Last Seen
June 30, 2026

ModeloRAT is a remote access trojan associated with a campaign that distributes a counterfeit ad-blocker extension.

Overview

ModeloRAT is a remote access trojan associated with a campaign that distributes a counterfeit ad-blocker extension. The operation, linked to ClickFix attacks, leverages the fake extension to crash browsers and establish attacker control over infected hosts. This underscores the risk of malicious browser extensions being used as delivery and persistence vectors in contemporary malware campaigns.

Related Threat Clusters

Recent Intelligence Reports

  • Mistic Malware Blends Into Microsoft Endpoint Components Using Malicious EndpointDlp.dll — Gbhackers · June 30, 2026
  • Stealthy Mistic Backdoor Targets Enterprise Networks via KongTuke Ransomware Access Broker — Rescana · June 25, 2026
  • Be on the lookout for Mistic, a new backdoor used by ransomware broker — Csoonline · June 24, 2026
  • Symantec’s Threat Hunter Team observed ModeloRAT — www.security.com · June 24, 2026
  • Stealthy Mistic backdoor linked to ransomware access broker KongTuke — Ground.News · June 24, 2026
  • Backdoor.Mistic: New Backdoor May be Linked to Ransomware Access Broker — Security · June 24, 2026
  • New Mistic backdoor enables stealthy long term access for ransomware brokers — Feeds.4Sysops · June 24, 2026
  • ModeloRAT and Mistic Backdoor Activity Linked to Ransomware Initial Access Broker — Gbhackers · June 24, 2026

CVSS v3.1 Breakdown