The SmartApeSG campaign relies on a fake CAPTCHA page combined with a ClickFix script to distribute several remote access threats, including Remcos RAT, NetSupport RAT, StealC, and Sectop RAT. The initial compromise sets off a staged infection chain in which each payload reaches out to its own command-and-control server. Delivery occurs through archive files that abuse DLL side-loading to launch the malware. The report also includes supporting indicators such as domains, IP addresses, file paths, and file hashes.
The analyst first recorded traffic from the ClickFix script at 17:11 UTC, with Remcos RAT communications beginning one minute later at 17:12 UTC. NetSupport RAT traffic appeared four minutes after that, StealC was observed roughly an hour later, and Sectop RAT emerged one hour and eighteen minutes after StealC. Investigators recovered file artifacts from both user and system directories and mapped them back to the specific malicious archives used in the chain.
Defenders should block the known malicious domains and IP addresses, while watching for execution of HTA files and suspicious archive extraction in user profile paths. Browser and email protections should be strengthened to reduce exposure to click-jacking and fake CAPTCHA delivery. Endpoint detection rules should also be tuned to identify DLL side-loading behavior and unexpected RAT processes.
If any of the listed indicators are found, isolate the impacted host, stop malicious processes, and collect memory and disk images for forensic analysis. Conduct a broad IOC sweep across the environment, update firewall controls to block the identified C2 endpoints, and reset any potentially compromised credentials.
Prerequisite: The Telemetry & Baseline Pre‑flight Check must have passed.
Rationale: This section details the precise execution of the adversary technique (TTP) designed to trigger the detection rule. The commands and narrative MUST directly reflect the TTPs identified and aim to generate the exact telemetry expected by the detection logic.
The adversary, having gained a foothold on the victim workstation, launches the Remcos RAT component of the SmartApeSG campaign. The RAT is configured to use 95.142.45.231:443 as its primary C2 endpoint. It first resolves the embedded domain fresicrto.top (fallback) and then opens a persistent HTTPS tunnel to the IP address. The traffic is generated by remcos.exe via the Windows WinHTTP API, which produces a Sysmon NetworkConnect event and a Windows Firewall log entry.
These actions map to T1102 (Web Service) for C2 communication and T1584.001 (Domain acquisition) as the domain is part of the payload.
Join SOC Prime's Detection as Code platform to improve visibility into threats most relevant to your business. To help you get started and drive immediate value, book a meeting now with SOC Prime experts.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
