{"id":11338,"date":"2026-03-14T04:04:18","date_gmt":"2026-03-14T04:04:18","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/03\/14\/32796\/"},"modified":"2026-03-14T04:04:18","modified_gmt":"2026-03-14T04:04:18","slug":"32796","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/03\/14\/32796\/","title":{"rendered":"SmartApeSG campaign uses ClickFix page to push Remcos RAT, (Sat, Mar 14th)"},"content":{"rendered":"<p>    SmartApeSG campaign uses ClickFix page to push Remcos RAT, (Sat, Mar 14th)<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p><em><strong>Introduction<\/strong><\/em><\/p>\n<p>This diary describes a Remcos RAT infection that I generated in my lab on Thursday, 2026-03-11. This infection was from the SmartApeSG campaign that used a ClickFix-style fake CAPTCHA page.<\/p>\n<p>My previous in-depth diary about a SmartApeSG (ZPHP, HANEYMANEY)\u00a0was i<a href=\"https:\/\/isc.sans.edu\/diary\/SmartApeSG+campaign+uses+ClickFix+page+to+push+NetSupport+RAT\/32474\">n November 2025<\/a>, when I saw NetSupport Manager RAT. Since then, I&#8217;ve fairly consistently seen what appears to be Remcos RAT from this campaign.<\/p>\n<p><em><strong>Finding SmartApeSG Activity<\/strong><\/em><\/p>\n<p>As previously noted, I find SmartApeSG indicators from the <a href=\"https:\/\/infosec.exchange\/@monitorsg\">Monitor SG account<\/a> on Mastodon, and I use <a href=\"https:\/\/urlscan.io\/search\/#*\">URLscan<\/a> to pivot on those indicators to find compromised websites with injected SmartApeSG script.<\/p>\n<p><em><strong>Details<\/strong><\/em><\/p>\n<p>Below is an image of HTML in a page from a legitimate but compromised website that shows the injected SmartApeSG script.<\/p>\n<p><a href=\"https:\/\/i0.wp.com\/isc.sans.edu\/diaryimages\/images\/2026-03-14-ISC-diary-image-01.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" alt=\"\" src=\"https:\/\/i0.wp.com\/isc.sans.edu\/diaryimages\/images\/2026-03-14-ISC-diary-image-01a.jpg?ssl=1\" style=\"border-width: 2px; border-style: solid;\"><\/a><br \/>\n<em>Shown above: Page from a legitimate but compromised site that highlights the injected SmartApeSG script.<\/em><\/p>\n<p>The injected SmartApeSG script generates a fake CAPTCHA-style &#8220;verify you are human&#8221; page, which displays ClickFix-style instructions after checking a box on the page. A screenshot from this infection is shown below, and it notes the ClickFix-style script injected into the user&#8217;s clipboard. Users are instructed to open a run window, paste the script into it, and hit the Enter key.<\/p>\n<p><a href=\"https:\/\/i0.wp.com\/isc.sans.edu\/diaryimages\/images\/2026-03-14-ISC-diary-image-02.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" alt=\"\" src=\"https:\/\/i0.wp.com\/isc.sans.edu\/diaryimages\/images\/2026-03-14-ISC-diary-image-02a.jpg?ssl=1\" style=\"border-width: 2px; border-style: solid;\"><\/a><br \/>\n<em>Shown above: Fake CAPTCHA page generated by a legitimate but compromised site, showing the ClickFix-style command.<\/em><\/p>\n<p>I used Fiddler to reveal URLS from the HTTPS traffic, and I recorded the traffic and viewed it in Wireshark. Traffic from the infection chain is shown in the image below.<\/p>\n<p><a href=\"https:\/\/i0.wp.com\/isc.sans.edu\/diaryimages\/images\/2026-03-14-ISC-diary-image-03.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" alt=\"\" src=\"https:\/\/i0.wp.com\/isc.sans.edu\/diaryimages\/images\/2026-03-14-ISC-diary-image-03a.jpg?ssl=1\" style=\"border-width: 2px; border-style: solid;\"><\/a><br \/>\n<em>Shown above: Traffic from the infection in Fiddler and Wireshark.<\/em><\/p>\n<p>After running the ClickFix-style instructions, the malware was sent as a ZIP archive and saved to disk with a <span style=\"font-family:Courier New,Courier,monospace;\">.pdf<\/span> file extension. This appears to be Remcos RAT in a malicious package that uses DLL side-loading to run the malware. This infection was made persistent with an update to the Windows Registry.<\/p>\n<p><a href=\"https:\/\/i0.wp.com\/isc.sans.edu\/diaryimages\/images\/2026-03-14-ISC-diary-image-04.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" alt=\"\" src=\"https:\/\/i0.wp.com\/isc.sans.edu\/diaryimages\/images\/2026-03-14-ISC-diary-image-04a.jpg?ssl=1\" style=\"border-width: 2px; border-style: solid;\"><\/a><br \/>\n<em>Shown above: Malware from the infection persistent on an infected Windows host.<\/em><\/p>\n<p><em><strong>Indicators of Compromise<\/strong><\/em><\/p>\n<p>Injected SmartApeSG script injected into page from legitimate but compromised site:<\/p>\n<ul>\n<li><span style=\"font-family:Courier New,Courier,monospace;\">hxxps[:]\/\/cpajoliette[.]com\/d.js<\/span><\/li>\n<\/ul>\n<p>Traffic to domain hosting the fake CAPTCHA page:<\/p>\n<ul>\n<li><span style=\"font-family:Courier New,Courier,monospace;\">hxxps[:]\/\/retrypoti[.]top\/endpoint\/signin-cache.js<\/span><\/li>\n<li><span style=\"font-family:Courier New,Courier,monospace;\">hxxps[:]\/\/retrypoti[.]top\/endpoint\/login-asset.php?Iah0QU0N<\/span><\/li>\n<li><span style=\"font-family:Courier New,Courier,monospace;\">hxxps[:]\/\/retrypoti[.]top\/endpoint\/handler-css.js?00109a4cb788daa811<\/span><\/li>\n<\/ul>\n<p>Traffic generated by running the ClickFix-style script:<\/p>\n<ul>\n<li>\n<span style=\"font-family:Courier New,Courier,monospace;\">hxxp[:]\/\/forcebiturg[.]com\/boot<\/span>\u00a0 &lt;&#8211; 302 redirect to HTTPS URL<\/li>\n<li>\n<span style=\"font-family:Courier New,Courier,monospace;\">hxxps[:]\/\/forcebiturg[.]com\/boot<\/span>\u00a0 &lt;&#8211; returned HTA file<\/li>\n<li>\n<span style=\"font-family:Courier New,Courier,monospace;\">hxxp[:]\/\/forcebiturg[.]com\/proc<\/span>\u00a0 &lt;&#8211; 302 redirect to HTTPS URL<\/li>\n<li>\n<span style=\"font-family:Courier New,Courier,monospace;\">hxxps[:]\/\/forcebiturg[.]com\/proc<\/span>\u00a0 &lt;&#8211; returned ZIP archive archive with files for Remcos RAT<\/li>\n<\/ul>\n<p>Post-infection traffic for Remcos RAT:<\/p>\n<ul>\n<li>\n<span style=\"font-family:Courier New,Courier,monospace;\">193.178.170[.]155:443<\/span> &#8211; TLSv1.3 traffic using self-signed certificate<\/li>\n<\/ul>\n<p>Example of ZIP archive for Remcos RAT:<\/p>\n<ul>\n<li>SHA256 hash: <span style=\"font-family:Courier New,Courier,monospace;\">b170ffc8612618c822eb03030a8a62d4be8d6a77a11e4e41bb075393ca504ab7<\/span>\n<\/li>\n<li>File size: 92,273,195 bytes<\/li>\n<li>File type: Zip archive data, at least v2.0 to extract, compression method=deflate<\/li>\n<li>Example of saved file location: <span style=\"font-family:Courier New,Courier,monospace;\">C:Users[username]AppDataLocalTemp594653818594653818.pdf<\/span>\n<\/li>\n<\/ul>\n<p>Of note, the files, URLs and domains for SmartApeSG activity change on a near-daily basis, and the indicators described in this article are likely no longer current. However, the overall patterns of activity for SmartApeSG have remained fairly consistent over the past several months.<\/p>\n<p>&#8212;<br \/>\nBradley Duncan<br \/>\nbrad [at] malware-traffic-analysis.net<\/p>\n<p> (c) SANS Internet Storm Center. https:\/\/isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.<\/p><\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><\/p>\n<p> \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/isc.sans.edu\/diary\/rss\/32796\">Go to isc.sans.edu<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>SmartApeSG campaign uses ClickFix page to push Remcos RAT, (Sat, Mar 14th) Introduction This diary describes a Remcos RAT infection that I generated in my lab on Thursday, 2026-03-11. This infection was from the SmartApeSG campaign that used a ClickFix-style fake CAPTCHA page. My previous in-depth diary about a SmartApeSG (ZPHP, HANEYMANEY)\u00a0was in November 2025, [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[56],"tags":[69],"class_list":["post-11338","post","type-post","status-publish","format-standard","hentry","category-isc-sans-edu","tag-isc-sans-edu"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/11338"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=11338"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/11338\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=11338"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=11338"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=11338"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}