Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
remote-access-implantcredential-stealer-activityphishing-campaign-intelligenceloader-delivery-mechanism

SmartApeSG ClickFix Campaign Delivers Remcos, NetSupport, StealC, and Sectop RAT

Updated 23d agoFirst seen Mar 25, 20267 sources

Researchers documented a SmartApeSG malware campaign using fake CAPTCHA pages and the ClickFix social-engineering technique to trick victims into launching an initial script that led to a multi-stage infection. In observed intrusions, Remcos RAT executed first, followed within minutes by NetSupport RAT, then StealC, and later Sectop RAT identified as ArechClient2. The activity relied on compromised web infrastructure, rotating delivery domains, attacker-controlled command-and-control servers, and multiple payload packages, with several stages using DLL side-loading through legitimate executables while NetSupport RAT was deployed as a legitimate remote administration tool configured for malicious control.

Separate analysis tied Sectop RAT / ArechClient2 to additional follow-on infections, including a chain where a victim seeking cracked software downloaded a password-protected archive that installed Lumma Stealer before fetching a 64-bit DLL from enotsosun[.]pw and executing it via rundll32 using the LoadForm export. Investigators reported concrete indicators including malware hashes, filenames, persistence artifacts, malicious URLs, and network traffic from Sectop RAT to 91.92.241[.]102 over ports 9000 and 443, reinforcing that ArechClient2 is being used across varied delivery lures as part of broader credential theft and remote-access operations.

Share:
SmartApeSG ClickFix Campaign Delivers Remcos, NetSupport, StealC, and Sectop RAT
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
May 27, 202628d ago

SmartApeSG ClickFix chain seen delivering unidentified RAT then NetSupport RAT

On 2026-05-27, a SmartApeSG ClickFix infection chain was observed delivering an unidentified initial RAT that communicated with 89.110.110[.]119:443, followed by a malicious NetSupport Manager RAT package communicating with 185.163.47[.]217:443. The report identified lure and delivery infrastructure including hiddenplanetlab[.]top and silverharvestnetwork[.]com, plus installation and persistence files such as processor.vbs, token.bat, and setup.cab under C:\ProgramData.

Unidentified RAT pushes NetSupport RAT - SANS ISC
Apr 17, 20262mo ago

Lumma Stealer infection chain seen delivering Sectop RAT

A separate malware infection chain was documented in which a user searching for cracked software downloaded a password-protected archive that installed Lumma Stealer, followed by a Sectop RAT (ArechClient2) DLL executed via rundll32. The report included C2 domains, malicious URLs, hashes, persistence details, and network traffic to 91.92.241[.]102 over ports 9000 and 443.

Mar 31, 20263mo ago

VMRay publishes analysis of ArechClient2 SectopRAT activity

VMRay released a report focused on ArechClient2 SectopRAT, adding technical analysis of this malware family and its behavior. The reference indicates public reporting on the malware by March 31, 2026.

Mar 24, 20263mo ago

SmartApeSG infection chain expands to multiple malware families

On March 24, 2026, Bradley Duncan documented a SmartApeSG infection in which a victim executing a ClickFix script received Remcos RAT first, then NetSupport RAT, followed by StealC and finally Sectop RAT (ArechClient2). The analysis also identified delivery infrastructure, C2 servers, hashes, and use of DLL side-loading for several payloads.

Mar 12, 20263mo ago

SmartApeSG observed using ClickFix to deliver Remcos RAT

A SmartApeSG campaign was observed using a fake CAPTCHA ClickFix page to infect victims and deliver Remcos RAT. Malware-Traffic-Analysis.net published supporting sample files for this infection chain tied to activity dated March 12, 2026.

Nov 12, 20257mo ago

Earlier SmartApeSG ClickFix campaign reported pushing NetSupport RAT

An earlier SANS ISC diary reported SmartApeSG using a ClickFix page to deliver NetSupport RAT, showing the campaign had already been using fake CAPTCHA lures before the March 2026 multi-malware chain. The exact activity date is not provided in the reference, so the publication date is used.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

4 LINKEDOpen in app
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

SmartApeSG ClickFix Campaign Delivers Remcos, NetSupport, StealC, and Sectop RAT | Mallory