ZPHP Campaign Delivering Remcos RAT Impacting SLTTs
ID: 8f19fd9e-b77b-533b-9cbe-605689f409bf
STIX ID: report--8f19fd9e-b77b-533b-9cbe-605689f409bf
Feed Name: CISecurity.org Insights Blog
CIS CTI warns of an ongoing ZPHP/SmartApeSG campaign targeting U.S. SLTT organizations that injects malicious JavaScript into compromised sites to display fake Cloudflare Turnstile CAPTCHAs and use the ClickFix clipboard trick to make victims execute a command that stages an HTA/PowerShell chain and deploys Remcos RAT (hidden via steganography and DLL sideloading); the report provides technical indicators, example C2 IPs, impact metrics (IDS alerts and nearly 500,000 MDBR-blocked DNS requests across 162 organizations), and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
