SmartApeSG Campaign Distributes Multiple RATs via ClickFix Technique

SmartApeSG Campaign Distributes Multiple RATs via ClickFix Technique

First seen 18 Jun 2026, 16:44 UTC socprime.comisc.sans.edu 81% similarity 72.5

Article Content

Browse articles
ThreatCluster

The SmartApeSG campaign employs a fake CAPTCHA page and ClickFix script to deliver various remote access trojans (RATs) including Remcos, NetSupport, StealC, and Sectop RAT. The attack begins with Remcos RAT, which communicates with its command-and-control server shortly after execution. Subsequent malware, such as NetSupport RAT, is delivered approximately four minutes later, followed by StealC and Sectop RAT at intervals of one hour and eighteen minutes. The malware is packaged in archive files that utilize DLL side-loading to execute. Indicators of compromise include specific domains, IP addresses, and file hashes associated with the malware. Security measures recommended include blocking known malicious domains and enhancing endpoint detection rules. The campaign has been observed to change indicators frequently, necessitating ongoing vigilance.

Key Points: • SmartApeSG campaign uses fake CAPTCHA and ClickFix to deploy multiple RATs. • Remcos RAT initiates the infection, followed by NetSupport, StealC, and Sectop RATs. • Defenders are advised to block malicious domains and strengthen endpoint detection.

ThreatCluster AI How this analysis works

Timeline

2026-03-24
SmartApeSG campaign activity observed
Indicators of the SmartApeSG campaign were noted, including the delivery of Remcos RAT followed by NetSupport RAT and others.
ISC SANS
2026-06-18
SmartApeSG campaign detailed by SOC Prime
SOC Prime reported on the SmartApeSG campaign's use of ClickFix to deliver multiple RATs, including Remcos and others.
socprime.com

Community

Browse all →