s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-js.smartapesg

📛 Threat Title

Malware family: SmartApeSG

Category: SmartApeSG First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `js.smartapesg`. Printable name: SmartApeSG. Aliases: HANEYMANEY,ZPHP.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain js.smartapesg VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/js.smartapesg

IOC database

Type
domain
Value
js.smartapesg
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-js.smartapesg

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/js.smartapesg

References (1)

Remediations (10)

  • web:cybersecuritynews.com

    A threat campaign known as SmartApeSG — also tracked under the names ZPHP and HANEYMANEY — has been observed pushing multiple strains of malware through a social engineering technique called ClickFix. The campaign, active as recently as March 24, 2026, delivered four separate malware payloads to a single infected host in one session: Remcos RAT, NetSupport RAT, StealC, and Sectop RAT, also ...

  • web:isc.sans.edu

    This campaign pushes malicious NetSupport RAT packages for its initial malware infection, and I've seen follow-up malware from these NetSupport RAT infections. How To Find SmartApeSG Activity I can usually find SmartApeSG indicators from the Monitor SG account on Mastodon.

  • web:malpedia.caad.fkie.fraunhofer.de

    According to Proofpoint, this is a cluster of fake update campaigns delivering payloads like NetSupportManager RAT and Lumma Stealer.

  • web:socprime.com

    The SmartApeSG campaign relies on a fake CAPTCHA page combined with a ClickFix script to distribute several remote access threats, including Remcos RAT, NetSupport RAT, StealC, and Sectop RAT.

  • web:threatfox.abuse.ch

    ThreatFox Database Indicators of Compromise (IOCs) on ThreatFox are associated with a certain malware fas. A malware sample can be associated with only one malware family . The page below gives you an overview on indicators of compromise associated with js. smartapesg . You can also get this data through the ThreatFox API. Database Entry

  • web:undercodetesting.com

    Introduction The SmartApeSG campaign represents a sophisticated evolution in malware distribution, leveraging the increasingly prevalent ClickFix social engineering technique to deliver not just one, but a cascade of Remote Access Trojans (RATs) and information stealers. This multi-stage attack, recently analyzed by the SANS Internet Storm Center, demonstrates how threat actors are combining ...

  • web:vpncentral.com

    A fresh SmartApeSG campaign is using ClickFix fake CAPTCHA lures to deliver several malware strains from one user action. SANS Internet Storm Center said a March 24, 2026 infection it analyzed dropped Remcos RAT, NetSupport RAT, StealC, and Sectop RAT, also known as ArechClient2, onto the same Windows host over a span of about two and a half hours. That makes this campaign more dangerous than ...

  • web:www.blumira.com

    SmartApeSG evolves its FakeUpdate attacks with advanced cmd.exe obfuscation techniques to mshta execution. Learn how the attack works and how to detect it.

  • web:www.malware-traffic-analysis.net

    Shown above: SmartApeSG script injected into page from compromised website. Shown above: SmartApeSG fake CAPTCHA page with ClickFix instructions. Shown above: Malware delivered through SmartApeSG persistent on an infected Windows host. Click here to return to the main page.

  • web:www.threatdown.com

    SmartApeSG , tested on June 11, 2024 Distribution Social engineering attacks via fake browser updates are increasingly common. Criminals inject code into compromised websites, which then present unsuspecting website users with malware downloads disguised as browser updates. With little effort, threat actors can trick victims into executing malicious code and gain initial access to their ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.