SmartApeSG Campaign Distributes Multiple RATs via ClickFix Technique
ID: 034d3a72-8fac-5bab-8728-50dfe33bdfc8
STIX ID: report--034d3a72-8fac-5bab-8728-50dfe33bdfc8
Feed Name: ThreatCluster
The SmartApeSG campaign leverages fake CAPTCHA pages and a ClickFix script to distribute multiple RATs (Remcos, NetSupport, StealC, Sectop) packaged in archives that use DLL side‑loading for execution. Remcos typically initiates the infection followed by staged delivery of other RATs over minutes to hours; the report lists associated domains, IP addresses, and file hashes as IoCs, notes frequent indicator rotation, and recommends blocking malicious domains and improving endpoint detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
