Executive Summary
In March 2026, the SmartApeSG campaign employed the ClickFix technique to deliver a sequence of malware, including Remcos RAT, NetSupport RAT, StealC, and Sectop RAT (ArechClient2). The attack began with a fake CAPTCHA page that tricked users into executing a malicious script, leading to the staged deployment of these remote access tools and information stealers over several hours. This multi-stage infection allowed attackers to establish persistent access and exfiltrate sensitive data from compromised systems. The SmartApeSG campaign underscores the evolving sophistication of social engineering tactics, particularly the use of ClickFix to bypass traditional security measures. Organizations must remain vigilant against such deceptive techniques, as they continue to be refined and pose significant threats to cybersecurity.
Why This Matters Now
The SmartApeSG campaign highlights the increasing sophistication of social engineering attacks, particularly the use of the ClickFix technique to bypass traditional security measures. Organizations must remain vigilant against such deceptive tactics, as they continue to evolve and pose significant threats to cybersecurity.
Attack Path Analysis
The SmartApeSG campaign initiated with users visiting compromised websites that displayed fake CAPTCHA pages, leading to the execution of malicious scripts. These scripts downloaded and executed multiple malware payloads, including Remcos RAT, NetSupport RAT, StealC, and Sectop RAT, enabling attackers to escalate privileges and move laterally within the network. The malware established command and control channels to communicate with external servers, facilitating data exfiltration and further malicious activities. The campaign's impact included unauthorized access, data theft, and potential disruption of services.
Kill Chain Progression
Initial Compromise
Description
Users visited compromised websites that displayed fake CAPTCHA pages, leading to the execution of malicious scripts.
Related CVEs
CVE-2017-0199
CVSS 7.8A remote code execution vulnerability in Microsoft Office and WordPad allows attackers to execute arbitrary code via specially crafted files.
Affected Products:
Microsoft Office – 2010, 2013, 2016
Microsoft WordPad – N/A
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
User Execution: Malicious Link
Command and Scripting Interpreter: PowerShell
Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
Process Injection
Obfuscated Files or Information
Screen Capture
Exfiltration Over C2 Channel
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure all system components and software are protected from known vulnerabilities
Control ID: 6.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – User and Device Authentication
Control ID: 3.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
Multi-stage malware campaign with StealC credential theft and lateral movement capabilities threatens transaction security, customer data, and regulatory compliance requirements.
Health Care / Life Sciences
RAT deployment enabling data exfiltration and east-west traffic compromise poses severe HIPAA compliance risks and patient data protection vulnerabilities.
Computer Software/Engineering
ClickFix technique targeting legitimate websites creates supply chain risks, intellectual property theft through multiple RAT payloads and segmentation bypass threats.
Banking/Mortgage
Remcos and NetSupport RAT C2 communications combined with credential harvesting capabilities threaten financial transaction integrity and regulatory compliance frameworks.
Sources
- SmartApeSG campaign pushes Remcos RAT, NetSupport RAT, StealC, and Sectop RAT (ArechClient2), (Wed, Mar 25th)https://isc.sans.edu/diary/rss/32826Verified
- SmartApeSG campaign uses ClickFix page to push Remcos RAThttps://isc.sans.edu/diary/SmartApeSG%2Bcampaign%2Buses%2BClickFix%2Bpage%2Bto%2Bpush%2BRemcos%2BRAT/32796/Verified
- Hackers Use Fake Browser Updates to Deploy NetSupport RAT & StealC Malware on Windowshttps://cyberpress.org/hackers-use-fake-browser-updates-to-deploy-netsupport-rat/Verified
- Hacked US law firm sites tapped to spread various malwarehttps://www.scworld.com/brief/hacked-us-law-firm-sites-tapped-to-spread-various-malwareVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to the SmartApeSG campaign as it could likely limit the attacker's ability to escalate privileges, move laterally, and exfiltrate data by enforcing strict segmentation and controlled egress policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: While Aviatrix Zero Trust CNSF may not prevent the initial execution of malicious scripts from compromised websites, it could likely limit the subsequent actions these scripts attempt within the cloud environment.
Control: Zero Trust Segmentation
Mitigation: Aviatrix Zero Trust Segmentation could likely constrain the malware's ability to escalate privileges by enforcing strict access controls and limiting communication between workloads.
Control: East-West Traffic Security
Mitigation: Aviatrix East-West Traffic Security could likely limit the malware's ability to move laterally by monitoring and controlling internal traffic between workloads.
Control: Multicloud Visibility & Control
Mitigation: Aviatrix Multicloud Visibility & Control could likely detect and restrict unauthorized command and control communications by providing comprehensive monitoring and control over outbound traffic.
Control: Egress Security & Policy Enforcement
Mitigation: Aviatrix Egress Security & Policy Enforcement could likely limit data exfiltration by controlling and monitoring outbound traffic to prevent unauthorized data transfers.
While Aviatrix Zero Trust CNSF may not entirely prevent unauthorized access, it could likely reduce the scope of data theft and service disruption by limiting the attacker's reach within the cloud environment.
Impact at a Glance
Affected Business Functions
- Legal Services
- Client Confidentiality
- Document Management
Estimated downtime: 7 days
Estimated loss: $50,000
Confidential client information, legal documents, and sensitive communications.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict lateral movement and limit the spread of malware within the network.
- • Deploy Egress Security & Policy Enforcement to monitor and control outbound traffic, preventing unauthorized data exfiltration.
- • Utilize Threat Detection & Anomaly Response systems to identify and respond to malicious activities promptly.
- • Enforce East-West Traffic Security to monitor internal communications and detect unauthorized access attempts.
- • Apply Inline IPS (Suricata) to inspect and block known exploit patterns and malicious payloads at the network perimeter.



