Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

SmartApeSG Uses ClickFix to Deploy NetSupport RAT

The SmartApeSG campaign, also known as ZPHP and HANEYMANEY, continues to evolve its infection tactics, pivoting to ClickFix-style attack vectors.Security researchers have documented the campaign’s latest methodology, which uses deceptive fake CAPTCHA…

The SmartApeSG campaign, also known as ZPHP and HANEYMANEY, continues to evolve its infection tactics, pivoting to ClickFix-style attack vectors.Security researchers have documented the campaign’s latest methodology, which uses deceptive fake CAPTCHA pages to trick users into executing malicious commands that ultimately deploy NetSupport RAT a Remote Access Trojan capable of giving attackers complete control over compromised Windows systems.First identified in June 2024, SmartApeSG has demonstrated consistent development of its attack infrastructure.The campaign initially relied on fake browser update pages to deceive users, but has since transitioned to the more effective ClickFix technique.This evolution reflects adversaries’ ongoing efforts to improve social engineering effectiveness and bypass traditional security awareness training that users may have developed against outdated attack methods.Attack Mechanism and Infection ChainThe infection begins when users visit compromised websites containing hidden injected scripts. These scripts are designed to activate under specific conditions, displaying a fake CAPTCHA-style verification page that mimics legitimate security checks.Injected SmartApeSG script in a page from the compromised site.When users click the “verify you are human” button, the attack sequence initiates automatically.The malicious script performs three critical actions. First, it injects malicious content directly into the Windows host’s clipboard.Second, it displays a pop-up with instructions directing users to open the Windows Run dialog, paste the clipboard content, and execute it.The clipboard-injected content contains a command string utilizing the mshta command a Windows utility that executes HTML applications to retrieve and execute additional malicious content remotely.ClickFix directions to paste content (a malicious command) into the Run window.This social engineering approach is particularly practical because it leverages user trust in system interface elements and appears to originate from legitimate website operations.The ClickFix technique has proven successful across multiple campaigns, and SmartApeSG’s implementation demonstrates how threat actors quickly adopt proven attack methodologies.Once executed, the malicious command downloads and installs NetSupport RAT onto the compromised system.The malware establishes persistence through a strategically placed Start Menu shortcut that automatically executes a JavaScript file stored in the user’s AppData\Local\Temp directory.The malicious NetSupport RAT package, persistent on an infected Windows host.This JavaScript file subsequently launches the NetSupport RAT executable located in a subdirectory under C:\ProgramData, ensuring the malware remains active across system reboots.NetSupport RAT is a powerful remote access tool that grants attackers comprehensive control capabilities, including file access, command execution, and surveillance functionality. Security researchers have observed follow-up malware infections deploying from NetSupport RAT infections, suggesting the initial compromise often serves as a staging point for additional malicious payloads.Detection and MonitoringSecurity analysts tracking SmartApeSG activity typically identify campaign indicators through dedicated threat intelligence monitoring.Researchers can pivot on these indicators using URLscan to identify compromised websites that host the malicious scripts.However, the campaign demonstrates sophisticated operational security practices the infection chain does not consistently activate, as adversaries appear to implement conditional execution logic based on factors such as time of day or source IP address, potentially preventing sandbox analysis and repeated infection attempts from the same network.Organizations should implement robust email filtering and web gateway protections to block access to known compromised websites.User security awareness training should specifically address ClickFix-style attacks and the dangers of executing unfamiliar commands through system utilities.Endpoint detection and response solutions should monitor for suspicious MSHTA execution and NetSupport RAT artifacts on Windows systems.Follow us on Google News, LinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Based on reporting by GBHackers.

Advertisement
AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories