logo

SmartApeSG ClickFix Campaign Spreads Remcos, NetSupport RAT, StealC, Sectop RAT

ID: 0e92693a-50ac-561b-97d3-8cd6bc9e6137

STIX ID: report--0e92693a-50ac-561b-97d3-8cd6bc9e6137

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-03-25

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

A SmartApeSG ClickFix campaign observed on March 24, 2026, uses compromised websites to redirect victims to a fake CAPTCHA that coerces running a malicious script. The script retrieves an HTA which downloads a ZIP-disguised payload chain, resulting in staged deployment of Remcos RAT, NetSupport RAT, StealC infostealer, and Sectop RAT; attackers rely on DLL side-loading and time-delayed execution to maintain persistence and evade detection, and defenders are advised to monitor script-based execution, outbound connections, and DLL side-loading behaviors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.