216.73.216.226

Campaign uses ClickFix page to push NetSupport RAT

· Published 08/12/2025 17:41 · Modified 21/12/2025 18:49

Export JSON

Essential information

Published
08/12/2025 17:41
Modified
21/12/2025 18:49
Tags
2025-12-08 clickfix clipboard injection fake captcha haneymaney netsupport rat persistence zphp
Related entities
3 observables, 1 intrusion sets (apt), 7 techniques (mitre), 1 malware, 2 others

Description

The SmartApeSG campaign, also known as or , has evolved from using fake browser update pages to employing -style pages. This campaign distributes malicious packages as its initial infection vector. The attack chain begins with an injected script on compromised websites, which, under certain conditions, displays a page. When users interact with this page, malicious content is injected into the Windows clipboard, prompting users to paste and execute it. This leads to the download and installation of , which maintains through a Start Menu shortcut. The campaign frequently changes domains, packages, and C2 servers to evade detection.

External references