logo

Scarlet Goldfinch’s year in ClickFix

ID: f877ae49-09c9-5de0-af3a-e268d28c9b68

STIX ID: report--f877ae49-09c9-5de0-af3a-e268d28c9b68

Feed Name: Red Canary

Threat Score
70/100

Date Published: 2026-03-26

Date Updated: 2026-04-29

Author: Red Canary Intelligence

...
...

Red Canary analyzes the Scarlet Goldfinch activity cluster (aka SmartApeSG/ZPHP), which uses malicious "paste and run" web-based lures to get victims to execute obfuscated command lines that download HTA/archives and deploy Remcos and NetSupport Manager via DLL sideloading; the report describes multiple evolutionary epochs of the campaign through 2025–early 2026, command-line obfuscation techniques, staging/persistence steps, and detection opportunities.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.