Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
SmartApeSG Campaign Infects Windows with Remote Access Malware

SmartApeSG Campaign Infects Windows with Remote Access Malware

Posted on June 1, 2026 By CWS

The SmartApeSG social engineering campaign has resurfaced, utilizing ClickFix scripts to surreptitiously install remote access malware on Windows systems. This operation targets users through deceptive verification pages, resulting in the execution of harmful scripts without the user’s awareness.

Deceptive Tactics and Infection Process

The campaign initiates when a user visits a compromised website displaying a fraudulent verification page. This page instructs users to execute a PowerShell or similar script, employing the ClickFix method. As the script runs, it silently connects to attacker-controlled servers, downloading the first stage of the malware infection.

Victims remain oblivious to the ongoing attack, while perpetrators gain persistent access to their systems. The Internet Storm Center identified this campaign after noticing a suspicious infection on May 27, 2026. Researcher Brad Duncan revealed that the campaign had been active for several weeks, generating encoded traffic to a command and control server.

Two-Stage Attack and Advanced Persistence

One of the notable aspects of this campaign is its two-stage design. The initial stage deploys an unidentified RAT, which communicates with its C2 server over TCP port 443, resembling standard web traffic. Once established, a secondary payload, the NetSupport Manager RAT, is downloaded, offering attackers remote control capabilities.

This second-stage RAT is installed to persist through system reboots. Post-installation, the setup scripts are automatically removed, complicating forensic investigations and indicating the campaign’s sophisticated planning.

Defense Strategies and Indicators of Compromise

To counteract these threats, it is crucial to monitor for unusual PowerShell activity linked to browser events, which could signify ClickFix script abuse. Additionally, blocking access to suspicious domains and observing for encoded traffic on port 443 can mitigate risks.

Security teams should remain vigilant as the campaign’s domains and file hashes change frequently. For the latest indicators, monitoring feeds like @monitorsg on Mastodon is advised. Important indicators of compromise include various URLs and IP addresses associated with the campaign’s operations.

In conclusion, the SmartApeSG campaign emphasizes the need for heightened vigilance and robust security measures to protect against evolving cyber threats. Staying informed and implementing effective defense strategies are essential in maintaining system integrity.

Cyber Security News Tags:Attack, C2 Server, ClickFix, cyber threat, Cybersecurity, infection chain, Malware, NetSupport, PowerShell, RAT, remote access, Security, SmartApeSG, Threat, Windows

Post navigation

Previous Post: OverlayPhantom Trojan Exploits Android Devices
Next Post: Red Hat npm Packages Breached by Credential-Stealing Malware

Related Posts

PlugX USB Worm Exploits DLL Sideloading Globally PlugX USB Worm Exploits DLL Sideloading Globally Cyber Security News
Python-based PyRAT with Cross-Platform Capabilities and Extensive Remote Access Features Python-based PyRAT with Cross-Platform Capabilities and Extensive Remote Access Features Cyber Security News
Critical Dolby Codec Vulnerability Exposes Android Devices to Code Execution Attacks Critical Dolby Codec Vulnerability Exposes Android Devices to Code Execution Attacks Cyber Security News
Malicious AI Extension Hijacks Search Data Malicious AI Extension Hijacks Search Data Cyber Security News
Livewire Filemanager Vulnerability Exposes Web Applications to RCE Attacks Livewire Filemanager Vulnerability Exposes Web Applications to RCE Attacks Cyber Security News
Hackers Actively Exploiting 7-Zip RCE Vulnerability in the Wild Hackers Actively Exploiting 7-Zip RCE Vulnerability in the Wild Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Five Hackers Admit to ATM Malware Attacks in Kansas
  • Venezuelan Nationals Admit to ATM Jackpotting in US
  • Stealthy Windows Backdoor Evades Detection Until Triggered
  • AI Utilized to Transfer PLC Exploit, Cost and Time Intensive
  • Iranian Hackers Use Job Offers to Spread Cross-Platform Malware

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Five Hackers Admit to ATM Malware Attacks in Kansas
  • Venezuelan Nationals Admit to ATM Jackpotting in US
  • Stealthy Windows Backdoor Evades Detection Until Triggered
  • AI Utilized to Transfer PLC Exploit, Cost and Time Intensive
  • Iranian Hackers Use Job Offers to Spread Cross-Platform Malware

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark