SmartApeSG ClickFix Campaign Spreads Remcos, NetSupport RAT, StealC, Sectop RAT
ID: 0e92693a-50ac-561b-97d3-8cd6bc9e6137
STIX ID: report--0e92693a-50ac-561b-97d3-8cd6bc9e6137
Feed Name: GBHackers
A SmartApeSG ClickFix campaign observed on March 24, 2026, uses compromised websites to redirect victims to a fake CAPTCHA that coerces running a malicious script. The script retrieves an HTA which downloads a ZIP-disguised payload chain, resulting in staged deployment of Remcos RAT, NetSupport RAT, StealC infostealer, and Sectop RAT; attackers rely on DLL side-loading and time-delayed execution to maintain persistence and evade detection, and defenders are advised to monitor script-based execution, outbound connections, and DLL side-loading behaviors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
