logo

SmartApeSG ClickFix Campaign Delivers Remcos, NetSupport RAT, StealC and Sectop RAT

ID: f012b558-159b-5cc4-ab66-6d0a71bfd4f1

STIX ID: report--f012b558-159b-5cc4-ab66-6d0a71bfd4f1

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-03-25

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

**SmartApeSG (aka ZPHP / HANEYMANEY)** uses compromised websites and a fake CAPTCHA 'ClickFix' flow to coerce users into pasting and running clipboard scripts that fetch and execute multiple staged payloads—Remcos RAT, NetSupport RAT, StealC, and Sectop RAT—on the same host; attackers employ DLL side-loading and HTA cleanup to evade detection, and the report includes domains (urotypos.com, fresicrto.top) and IPs (95.142.45.231, 185.163.47.220, 89.46.38.100, 195.85.115.11) to block and monitor.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.