#smartapesg — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #smartapesg, aggregated by home.social.
-
2026-08-21: SmartApeSG ClickFix campaign leads to two RATs
Indicators extracted from public reporting. Source: https://www.malware-traffic-analysis.net/2026/08/21/index.html
Pulse ID: 6a889165b097c9fea9c95d72
Pulse Link: https://otx.alienvault.com/pulse/6a889165b097c9fea9c95d72
Pulse Author: CyberHunter_NL
Created: 2026-08-21 17:56:53Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTML #HTTP #HTTPS #InfoSec #Malware #NET #OTX #OpenThreatExchange #RAT #RCE #SmartApeSg #bot #CyberHunter_NL
-
2026-08-21 (Friday): #SmartApeSG #ClickFix campaign leads to two RATs. A #pcap of the network traffic, some files from the infected Windows host, and a list of indicators are available at https://www.malware-traffic-analysis.net/2026/08/21/index.html
I did this before I realized someone had actually named one of the RATs. Thanks to @netresec for letting me know! https://www.levelblue.com/hubfs/Web/Library/Documents_pdf/CNCMachineRMS.pdf
-
2026-08-20 (Thursday): The domain today for #SmartApeSG #ClickFix activity was sedgeoriel[.]co
Compromised site
-->
www.ski-snowboardvancouver[.]ca/d.js (redirect)
-->
sedgeoriel[.]co/version/secure-json.js
-->
sedgeoriel[.]co/version/gateway-storage
-->
sedgeoriel[.]co/version/auth-payload.jsURLs from running the injected ClickFix text:
headlandsonnet[.]com/pros
-->
headlandsonnet[.]com/hungGot the infection late in the day, and I couldn't replicate it for a screenshot of the fake CAPTCHA/verification page.
Infection traffic shows this is the same family of initial RAT and post-infection RAT that I originally documented on my blog on August 12th at https://www.malware-traffic-analysis.net/2026/08/12/index.html
-
2025-08-18 (Tuesday): #SmartApeSG domain for fake CAPTCHA/human verification page is buttresshalcyon[.]top and cygnetrampart[.]top
I could pivot on these domains in urlscan.io to find some compromised websites and generate an infection. I saw the same post-infection traffic from the two RATs that I documented last week at https://www.malware-traffic-analysis.net/2026/08/12/index.html
Notably, when I ran the #ClickFix script injected into the clipboard, it didn't extract everything from the downloaded zip archive with the malicious package for DLL side-loading the initial RAT.
I had to extract all the files from the archive and run it manually to get a full infection chain.
I think the script used at some point for the initial infection is broken, which is why we're not seeing more on SmartApeSG recently.
-
2026-08-12 (Wednesday): #SmartApeSG #ClickFix leads to two RATs. A #pcap of the traffic, malware, artifacts and more info available at https://www.malware-traffic-analysis.net/2026/08/12/index.html
-
2026-07-31: SmartApeSG ClickFix campaign pushes unidentified RAT
Indicators extracted from public reporting. Source: https://www.malware-traffic-analysis.net/2026/07/31/index.html
Pulse ID: 6a79ac6adcf7b6da0537a5df
Pulse Link: https://otx.alienvault.com/pulse/6a79ac6adcf7b6da0537a5df
Pulse Author: CyberHunter_NL
Created: 2026-08-10 10:48:10Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTML #HTTP #HTTPS #InfoSec #Malware #NET #OTX #OpenThreatExchange #RAT #RCE #SmartApeSg #bot #CyberHunter_NL
-
2026-07-31 (Friday): #SmartApeSG #ClickFix campaign pushes unidentified #RAT malware. A #pcap of the infection traffic, the associated malware files, and further info available at https://www.malware-traffic-analysis.net/2026/07/31/index.html