Skip to content
  • Blog Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form

SmartApeSG Campaign Leverages ClickFix Technique to Deploy NetSupport RAT

Posted on November 14, 2025November 14, 2025 By CWS

The SmartApeSG marketing campaign, also referred to as ZPHP or HANEY MANEY, continues to evolve its assault strategies to compromise Home windows methods with malicious distant entry instruments.

First reported in June 2024, this marketing campaign has shifted from utilizing pretend browser replace pages to deploying subtle ClickFix-style methods.

The brand new strategy tips customers into pondering they should confirm their id by means of a pretend CAPTCHA web page, making the assault extra misleading and more durable to detect.

The marketing campaign primarily targets customers who go to compromised web sites displaying hidden malicious scripts. When sure circumstances are met, these scripts activate and current customers with a pretend “confirm you’re human” field.

Injected SmartApeSG script in a web page from the compromised website (Supply – Web Storm Heart)

The attackers use this intelligent approach to bypass consumer suspicion and trick them into taking actions that result in malware set up.

As soon as activated, the pretend CAPTCHA web page initiates a sequence of occasions designed to put in NetSupport RAT on the sufferer’s laptop.

Pretend CAPTCHA web page displayed by the compromised website (Supply – Web Storm Heart)

This distant entry device offers attackers full management over contaminated machines, permitting them to steal knowledge, monitor exercise, and deploy extra malware.

Web Storm Heart safety analysts recognized that the assault works by injecting malicious content material immediately right into a consumer’s clipboard after they click on the verification field.

The injected content material is a command string that makes use of the mshta command to retrieve and execute malicious code from attacker-controlled servers.

Multi-stage strategy

This method is especially efficient as a result of it bypasses conventional safety measures by counting on social engineering moderately than software program vulnerabilities.

The persistence mechanism operates by means of a intelligent Home windows trick. The malicious NetSupport RAT bundle maintains itself on contaminated computer systems by making a Begin Menu shortcut that runs a JavaScript file saved within the AppDataLocalTemp listing.

This JavaScript file then launches the precise NetSupport RAT executable situated within the C:ProgramData listing. This multi-stage strategy makes detection and elimination tougher for typical customers.

What makes SmartApeSG significantly harmful is the fixed evolution of its infrastructure. The domains, command and management servers, and malware packages change almost every day, making menace intelligence updates vital for safety groups.

Organizations ought to educate customers about clicking verification bins on web sites and implement network-level protections to dam connections to recognized malicious domains related to this marketing campaign.

Observe us on Google Information, LinkedIn, and X to Get Extra On the spot Updates, Set CSN as a Most popular Supply in Google.

Cyber Security News Tags:Campaign, ClickFix, Deploy, Leverages, NetSupport, RAT, SmartApeSG, Technique

Post navigation

Previous Post: Checkout.com Discloses Data Breach After Extortion Attempt
Next Post: NVIDIA NeMo Framework Vulnerabilities Allows Code Injection and Privilege Escalation

Related Posts

ClickFix Attacks Evolved With Weaponized Videos That Tricks Users via Self-infection Process Cyber Security News
Microsoft Unveils European Security Initiative to Target Cybercriminal Networks Cyber Security News
Surge in Attacks Targeting RSC-Enabled Services Worldwide Cyber Security News
ASUS Armoury Crate Vulnerability Let Attackers Escalate to System User on Windows Machine Cyber Security News
New GhostGrab Android Malware Silently Steals Banking Login Details and Intercept SMS for OTPs Cyber Security News
Kawa4096 Ransomware Attacking Multinational Organizations to Exfiltrate Sensitive Data Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Silver Fox Hackers Attacking Indian Entities with Income Tax Phishing Lures
  • New Phishing Kit with AI-assisted Development Attacking Microsoft Users to Steal Logins
  • Windows Event Logs Reveal the Messy Reality Behind ‘Sophisticated’ Cyberattacks
  • Top US Accounting Firm Sax Discloses 2024 Data Breach Impacting 220,000
  • 2.5 Million+ Malicious Request From Hackers Attacking Adobe ColdFusion Servers

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Silver Fox Hackers Attacking Indian Entities with Income Tax Phishing Lures
  • New Phishing Kit with AI-assisted Development Attacking Microsoft Users to Steal Logins
  • Windows Event Logs Reveal the Messy Reality Behind ‘Sophisticated’ Cyberattacks
  • Top US Accounting Firm Sax Discloses 2024 Data Breach Impacting 220,000
  • 2.5 Million+ Malicious Request From Hackers Attacking Adobe ColdFusion Servers

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2025 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark