logo

ZPHP Campaign Delivering Remcos RAT Impacting SLTTs

ID: 8f19fd9e-b77b-533b-9cbe-605689f409bf

STIX ID: report--8f19fd9e-b77b-533b-9cbe-605689f409bf

Feed Name: CISecurity.org Insights Blog

Threat Score
75/100

Date Published: 2026-03-17

Date Updated: 2026-04-19

...
...

CIS CTI warns of an ongoing ZPHP/SmartApeSG campaign targeting U.S. SLTT organizations that injects malicious JavaScript into compromised sites to display fake Cloudflare Turnstile CAPTCHAs and use the ClickFix clipboard trick to make victims execute a command that stages an HTA/PowerShell chain and deploys Remcos RAT (hidden via steganography and DLL sideloading); the report provides technical indicators, example C2 IPs, impact metrics (IDS alerts and nearly 500,000 MDBR-blocked DNS requests across 162 organizations), and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.