logo

SmartApeSG Campaign Distributes Multiple RATs via ClickFix Technique

ID: 034d3a72-8fac-5bab-8728-50dfe33bdfc8

STIX ID: report--034d3a72-8fac-5bab-8728-50dfe33bdfc8

Feed Name: ThreatCluster

Threat Score
75/100

Date Published: 2026-06-18

Date Updated: 2026-06-25

...
...

The SmartApeSG campaign leverages fake CAPTCHA pages and a ClickFix script to distribute multiple RATs (Remcos, NetSupport, StealC, Sectop) packaged in archives that use DLL side‑loading for execution. Remcos typically initiates the infection followed by staged delivery of other RATs over minutes to hours; the report lists associated domains, IP addresses, and file hashes as IoCs, notes frequent indicator rotation, and recommends blocking malicious domains and improving endpoint detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.