isc.sans.edu
SmartApeSG Campaign Distributes Multiple RATs via ClickFix Technique
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
The SmartApeSG campaign employs a fake CAPTCHA page and ClickFix script to deliver various remote access trojans (RATs) including Remcos, NetSupport, StealC, and Sectop RAT. The attack begins with Remcos RAT, which communicates with its command-and-control server shortly after execution. Subsequent malware, such as NetSupport RAT, is delivered approximately four minutes later, followed by StealC and Sectop RAT at intervals of one hour and eighteen minutes. The malware is packaged in archive files that utilize DLL side-loading to execute. Indicators of compromise include specific domains, IP addresses, and file hashes associated with the malware. Security measures recommended include blocking known malicious domains and enhancing endpoint detection rules. The campaign has been observed to change indicators frequently, necessitating ongoing vigilance.
Key Points: • SmartApeSG campaign uses fake CAPTCHA and ClickFix to deploy multiple RATs. • Remcos RAT initiates the infection, followed by NetSupport, StealC, and Sectop RATs. • Defenders are advised to block malicious domains and strengthen endpoint detection.