Related Threat Clusters
-
SmartApeSG Campaign Distributes Multiple RATs via ClickFix Technique
The SmartApeSG campaign employs a fake CAPTCHA page and ClickFix script to deliver various remote access trojans (RATs) including Remcos, NetSupport, StealC, and Sectop RAT. The attack begins with Remcos RAT, which…
2 articles · Updated June 18, 2026 -
SmartApeSG Targets Okendo Reviews Widget in Supply Chain Attack
On May 14, 2026, the SmartApeSG threat actor launched a supply chain attack by injecting malicious JavaScript into the Okendo Reviews widget, which is used by over 18,000 brands. This compromise allowed the delivery of…
4 articles · Updated June 19, 2026 -
SmartApeSG Campaign Distributes Multiple RATs via ClickFix Technique
The SmartApeSG campaign, also known as ZPHP and HANEYMANEY, has been observed delivering multiple remote access trojans (RATs) including Remcos RAT, NetSupport RAT, StealC, and Sectop RAT (ArechClient2) through a social…
3 articles · Updated March 25, 2026 -
GrayCharlie Compromises WordPress Sites to Distribute NetSupport RAT and Stealc
GrayCharlie, a threat actor, has been embedding malicious JavaScript into WordPress sites since mid-2023 to deliver the NetSupport RAT and Stealc malware to users. This group is associated with the SmartApeSG cluster…
2 articles · Updated February 23, 2026
Recent Intelligence Reports
- Hackers Abuse Third — Cybersecuritynews · June 19, 2026
- Smartapesg Delivers Remcos — socprime.com · June 18, 2026
- SmartApeSG Supply Chain Attack Targets Okendo | ThreatLabz - Zscaler, Inc. — Zscaler · June 18, 2026
- SmartApeSG campaign pushes Remcos RAT, NetSupport RAT, StealC, and Sectop RAT (ArechClient2), (Wed, Mar 25th) — Isc.Sans.Edu · March 25, 2026
- GrayCharlie Injects Malicious JavaScript into WordPress Sites to Deliver NetSupport RAT and Stealc — Cybersecuritynews · February 23, 2026