From Evasion to Evidence: Exploiting the Funneling Behavior of Injects
ID: 5d351bee-7aab-5838-bc3b-8fdfabb50ccb
STIX ID: report--5d351bee-7aab-5838-bc3b-8fdfabb50ccb
Feed Name: Censys Blog
Date Published: 2025-11-03
Date Updated: 2026-04-27
Author: Jean Pierre Ruiz Ocampo; Andrew Northern; Principal Security Researcher
This report analyzes the SmartApe multi-stage web-injection campaign that leverages transient injected pages and stage_2 redirect/TDS chokepoints to deliver a fake CAPTCHA, hijack the clipboard, and trick users into running mshta which fetches an encrypted HTA that decrypts to a PowerShell downloader; the final observed payload includes NetSupport RAT. The report provides IOCs (domains, URLs, a C2 IP), decryption/debugging steps, and shows how Censys can be used to find and monitor persistent infrastructure pivot points for detection and tracking.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
