DEV Community

Mark0
Mark0

Posted on

2026-07-31: SmartApeSG ClickFix campaign pushes unidentified RAT

The SmartApeSG ClickFix campaign involves using compromised legitimate websites to inject scripts that lead users to fake human verification pages. These pages instruct users to paste and execute malicious commands in the Windows Run dialog, a technique widely referred to as ClickFix.

Following the execution, an HTA file is downloaded which retrieves a ZIP archive. This archive contains a legitimate executable that utilizes DLL side-loading to deploy an unidentified Remote Access Trojan (RAT). The malware communicates with a C2 server over port 443, utilizing encrypted TCP traffic for command and control.


Read Full Article

Top comments (0)