TF-MAL-js.smartapesg
📛 Threat Title
Malware family: SmartApeSG
Description
ThreatFox malware family `js.smartapesg`. Printable name: SmartApeSG. Aliases: HANEYMANEY,ZPHP.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
js.smartapesg
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/js.smartapesg
IOC database
- Type
- domain
- Value
js.smartapesg- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-js.smartapesg
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/js.smartapesg
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:cybersecuritynews.com
A threat campaign known as SmartApeSG — also tracked under the names ZPHP and HANEYMANEY — has been observed pushing multiple strains of malware through a social engineering technique called ClickFix. The campaign, active as recently as March 24, 2026, delivered four separate malware payloads to a single infected host in one session: Remcos RAT, NetSupport RAT, StealC, and Sectop RAT, also ...
-
web:isc.sans.edu
This campaign pushes malicious NetSupport RAT packages for its initial malware infection, and I've seen follow-up malware from these NetSupport RAT infections. How To Find SmartApeSG Activity I can usually find SmartApeSG indicators from the Monitor SG account on Mastodon.
-
web:malpedia.caad.fkie.fraunhofer.de
According to Proofpoint, this is a cluster of fake update campaigns delivering payloads like NetSupportManager RAT and Lumma Stealer.
-
web:socprime.com
The SmartApeSG campaign relies on a fake CAPTCHA page combined with a ClickFix script to distribute several remote access threats, including Remcos RAT, NetSupport RAT, StealC, and Sectop RAT.
-
web:threatfox.abuse.ch
ThreatFox Database Indicators of Compromise (IOCs) on ThreatFox are associated with a certain malware fas. A malware sample can be associated with only one malware family . The page below gives you an overview on indicators of compromise associated with js. smartapesg . You can also get this data through the ThreatFox API. Database Entry
-
web:undercodetesting.com
Introduction The SmartApeSG campaign represents a sophisticated evolution in malware distribution, leveraging the increasingly prevalent ClickFix social engineering technique to deliver not just one, but a cascade of Remote Access Trojans (RATs) and information stealers. This multi-stage attack, recently analyzed by the SANS Internet Storm Center, demonstrates how threat actors are combining ...
-
web:vpncentral.com
A fresh SmartApeSG campaign is using ClickFix fake CAPTCHA lures to deliver several malware strains from one user action. SANS Internet Storm Center said a March 24, 2026 infection it analyzed dropped Remcos RAT, NetSupport RAT, StealC, and Sectop RAT, also known as ArechClient2, onto the same Windows host over a span of about two and a half hours. That makes this campaign more dangerous than ...
-
web:www.blumira.com
SmartApeSG evolves its FakeUpdate attacks with advanced cmd.exe obfuscation techniques to mshta execution. Learn how the attack works and how to detect it.
-
web:www.malware-traffic-analysis.net
Shown above: SmartApeSG script injected into page from compromised website. Shown above: SmartApeSG fake CAPTCHA page with ClickFix instructions. Shown above: Malware delivered through SmartApeSG persistent on an infected Windows host. Click here to return to the main page.
-
web:www.threatdown.com
SmartApeSG , tested on June 11, 2024 Distribution Social engineering attacks via fake browser updates are increasingly common. Criminals inject code into compromised websites, which then present unsuspecting website users with malware downloads disguised as browser updates. With little effort, threat actors can trick victims into executing malicious code and gain initial access to their ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.