The SmartApeSG ClickFix campaign involves using compromised legitimate websites to inject scripts that lead users to fake human verification pages. These pages instruct users to paste and execute malicious commands in the Windows Run dialog, a technique widely referred to as ClickFix.
Following the execution, an HTA file is downloaded which retrieves a ZIP archive. This archive contains a legitimate executable that utilizes DLL side-loading to deploy an unidentified Remote Access Trojan (RAT). The malware communicates with a C2 server over port 443, utilizing encrypted TCP traffic for command and control.
Top comments (0)