logo

SmartApeSG campaign pushes Remcos RAT, NetSupport RAT, StealC, and Sectop RAT (ArechClient2), (Wed, Mar 25th)

ID: 2c65c0a9-2aea-50ec-9982-9e7cc5619e26

STIX ID: report--2c65c0a9-2aea-50ec-9982-9e7cc5619e26

Feed Name: SANS ISC Diary

Threat Score
75/100

Date Published: 2026-03-25

Date Updated: 2026-04-19

...
...

The SmartApeSG campaign uses a compromised site with an injected ClickFix fake CAPTCHA to retrieve an HTA that installs Remcos RAT and subsequently delivers NetSupport RAT, StealC (infostealer), and Sectop RAT; the report includes infection timelines, associated domains/IPs, a file SHA256, file locations, and notes that follow-up packages use DLL side-loading and attacker-controlled legitimate tools.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.