SmartApeSG campaign pushes Remcos RAT, NetSupport RAT, StealC, and Sectop RAT (ArechClient2), (Wed, Mar 25th)
ID: 2c65c0a9-2aea-50ec-9982-9e7cc5619e26
STIX ID: report--2c65c0a9-2aea-50ec-9982-9e7cc5619e26
Feed Name: SANS ISC Diary
Threat Score
The SmartApeSG campaign uses a compromised site with an injected ClickFix fake CAPTCHA to retrieve an HTA that installs Remcos RAT and subsequently delivers NetSupport RAT, StealC (infostealer), and Sectop RAT; the report includes infection timelines, associated domains/IPs, a file SHA256, file locations, and notes that follow-up packages use DLL side-loading and attacker-controlled legitimate tools.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
