logo

From Evasion to Evidence: Exploiting the Funneling Behavior of Injects

ID: 5d351bee-7aab-5838-bc3b-8fdfabb50ccb

STIX ID: report--5d351bee-7aab-5838-bc3b-8fdfabb50ccb

Feed Name: Censys Blog

Threat Score
70/100

Date Published: 2025-11-03

Date Updated: 2026-04-27

Author: Jean Pierre Ruiz Ocampo; Andrew Northern; Principal Security Researcher

...
...

This report analyzes the SmartApe multi-stage web-injection campaign that leverages transient injected pages and stage_2 redirect/TDS chokepoints to deliver a fake CAPTCHA, hijack the clipboard, and trick users into running mshta which fetches an encrypted HTA that decrypts to a PowerShell downloader; the final observed payload includes NetSupport RAT. The report provides IOCs (domains, URLs, a C2 IP), decryption/debugging steps, and shows how Censys can be used to find and monitor persistent infrastructure pivot points for detection and tracking.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.