Scarlet Goldfinch’s year in ClickFix
ID: f877ae49-09c9-5de0-af3a-e268d28c9b68
STIX ID: report--f877ae49-09c9-5de0-af3a-e268d28c9b68
Feed Name: Red Canary
Threat Score
Red Canary analyzes the Scarlet Goldfinch activity cluster (aka SmartApeSG/ZPHP), which uses malicious "paste and run" web-based lures to get victims to execute obfuscated command lines that download HTA/archives and deploy Remcos and NetSupport Manager via DLL sideloading; the report describes multiple evolutionary epochs of the campaign through 2025–early 2026, command-line obfuscation techniques, staging/persistence steps, and detection opportunities.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
