home.social

#smartapesg — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #smartapesg, aggregated by home.social.

fetched live
  1. 2026-08-21: SmartApeSG ClickFix campaign leads to two RATs

    Indicators extracted from public reporting. Source: malware-traffic-analysis.net/2

    Pulse ID: 6a889165b097c9fea9c95d72
    Pulse Link: otx.alienvault.com/pulse/6a889
    Pulse Author: CyberHunter_NL
    Created: 2026-08-21 17:56:53

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #HTML #HTTP #HTTPS #InfoSec #Malware #NET #OTX #OpenThreatExchange #RAT #RCE #SmartApeSg #bot #CyberHunter_NL

  2. 2026-08-21 (Friday): #SmartApeSG #ClickFix campaign leads to two RATs. A #pcap of the network traffic, some files from the infected Windows host, and a list of indicators are available at malware-traffic-analysis.net/2

    I did this before I realized someone had actually named one of the RATs. Thanks to @netresec for letting me know! levelblue.com/hubfs/Web/Librar

  3. 2026-08-20 (Thursday): The domain today for #SmartApeSG #ClickFix activity was sedgeoriel[.]co

    Compromised site
    -->
    www.ski-snowboardvancouver[.]ca/d.js (redirect)
    -->
    sedgeoriel[.]co/version/secure-json.js
    -->
    sedgeoriel[.]co/version/gateway-storage
    -->
    sedgeoriel[.]co/version/auth-payload.js

    URLs from running the injected ClickFix text:

    headlandsonnet[.]com/pros
    -->
    headlandsonnet[.]com/hung

    Got the infection late in the day, and I couldn't replicate it for a screenshot of the fake CAPTCHA/verification page.

    Infection traffic shows this is the same family of initial RAT and post-infection RAT that I originally documented on my blog on August 12th at malware-traffic-analysis.net/2

  4. 2025-08-18 (Tuesday): #SmartApeSG domain for fake CAPTCHA/human verification page is buttresshalcyon[.]top and cygnetrampart[.]top

    I could pivot on these domains in urlscan.io to find some compromised websites and generate an infection. I saw the same post-infection traffic from the two RATs that I documented last week at malware-traffic-analysis.net/2

    Notably, when I ran the #ClickFix script injected into the clipboard, it didn't extract everything from the downloaded zip archive with the malicious package for DLL side-loading the initial RAT.

    I had to extract all the files from the archive and run it manually to get a full infection chain.

    I think the script used at some point for the initial infection is broken, which is why we're not seeing more on SmartApeSG recently.

  5. 2026-08-12 (Wednesday): #SmartApeSG #ClickFix leads to two RATs. A #pcap of the traffic, malware, artifacts and more info available at malware-traffic-analysis.net/2

  6. 2026-07-31: SmartApeSG ClickFix campaign pushes unidentified RAT

    Indicators extracted from public reporting. Source: malware-traffic-analysis.net/2

    Pulse ID: 6a79ac6adcf7b6da0537a5df
    Pulse Link: otx.alienvault.com/pulse/6a79a
    Pulse Author: CyberHunter_NL
    Created: 2026-08-10 10:48:10

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #HTML #HTTP #HTTPS #InfoSec #Malware #NET #OTX #OpenThreatExchange #RAT #RCE #SmartApeSg #bot #CyberHunter_NL

  7. 2026-07-31 (Friday): #SmartApeSG #ClickFix campaign pushes unidentified #RAT malware. A #pcap of the infection traffic, the associated malware files, and further info available at malware-traffic-analysis.net/2