Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
SmartApeSG Campaign Infects Windows with Remote Access Malware

SmartApeSG Campaign Infects Windows with Remote Access Malware

Posted on June 1, 2026 By CWS

The SmartApeSG social engineering campaign has resurfaced, utilizing ClickFix scripts to surreptitiously install remote access malware on Windows systems. This operation targets users through deceptive verification pages, resulting in the execution of harmful scripts without the user’s awareness.

Deceptive Tactics and Infection Process

The campaign initiates when a user visits a compromised website displaying a fraudulent verification page. This page instructs users to execute a PowerShell or similar script, employing the ClickFix method. As the script runs, it silently connects to attacker-controlled servers, downloading the first stage of the malware infection.

Victims remain oblivious to the ongoing attack, while perpetrators gain persistent access to their systems. The Internet Storm Center identified this campaign after noticing a suspicious infection on May 27, 2026. Researcher Brad Duncan revealed that the campaign had been active for several weeks, generating encoded traffic to a command and control server.

Two-Stage Attack and Advanced Persistence

One of the notable aspects of this campaign is its two-stage design. The initial stage deploys an unidentified RAT, which communicates with its C2 server over TCP port 443, resembling standard web traffic. Once established, a secondary payload, the NetSupport Manager RAT, is downloaded, offering attackers remote control capabilities.

This second-stage RAT is installed to persist through system reboots. Post-installation, the setup scripts are automatically removed, complicating forensic investigations and indicating the campaign’s sophisticated planning.

Defense Strategies and Indicators of Compromise

To counteract these threats, it is crucial to monitor for unusual PowerShell activity linked to browser events, which could signify ClickFix script abuse. Additionally, blocking access to suspicious domains and observing for encoded traffic on port 443 can mitigate risks.

Security teams should remain vigilant as the campaign’s domains and file hashes change frequently. For the latest indicators, monitoring feeds like @monitorsg on Mastodon is advised. Important indicators of compromise include various URLs and IP addresses associated with the campaign’s operations.

In conclusion, the SmartApeSG campaign emphasizes the need for heightened vigilance and robust security measures to protect against evolving cyber threats. Staying informed and implementing effective defense strategies are essential in maintaining system integrity.

Cyber Security News Tags:Attack, C2 Server, ClickFix, cyber threat, Cybersecurity, infection chain, Malware, NetSupport, PowerShell, RAT, remote access, Security, SmartApeSG, Threat, Windows

Post navigation

Previous Post: OverlayPhantom Trojan Exploits Android Devices
Next Post: Red Hat npm Packages Breached by Credential-Stealing Malware

Related Posts

RONINGLOADER Weaponized Weaponizes Signed Drivers to Disable Defender and Evade EDR Tools RONINGLOADER Weaponized Weaponizes Signed Drivers to Disable Defender and Evade EDR Tools Cyber Security News
Chinese State-Sponsored Hackers Attacking Telecommunications Infrastructure to Harvest Sensitive Data Chinese State-Sponsored Hackers Attacking Telecommunications Infrastructure to Harvest Sensitive Data Cyber Security News
SAP Security Update – Patch for Critical Vulnerabilities Allowing Code Execution and Injection Attacks SAP Security Update – Patch for Critical Vulnerabilities Allowing Code Execution and Injection Attacks Cyber Security News
ZAP JavaScript Engine Memory Leak Issue Impacts Active Scan Usage ZAP JavaScript Engine Memory Leak Issue Impacts Active Scan Usage Cyber Security News
Kea DHCP Server Vulnerability Let Remote Attacker Crash With a Single Crafted Packet Kea DHCP Server Vulnerability Let Remote Attacker Crash With a Single Crafted Packet Cyber Security News
Leak Zone Dark Web Forum Database Exposes 22 Million Users’ IP Addresses and Locations Leak Zone Dark Web Forum Database Exposes 22 Million Users’ IP Addresses and Locations Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Gamaredon Uses WinRAR Flaw to Target Ukraine with Malware
  • Cybercriminals Exploit Cloud Platforms to Conceal Attacks
  • HP VoIP Phones Vulnerability Threatens Enterprise Security
  • Oracle WebLogic Vulnerability Exploited: CISA Issues Alert
  • Diverging Reports Address Cybersecurity Challenges

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Gamaredon Uses WinRAR Flaw to Target Ukraine with Malware
  • Cybercriminals Exploit Cloud Platforms to Conceal Attacks
  • HP VoIP Phones Vulnerability Threatens Enterprise Security
  • Oracle WebLogic Vulnerability Exploited: CISA Issues Alert
  • Diverging Reports Address Cybersecurity Challenges

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark