This report documents an infection chain observed on September 15, 2026, starting with a SmartApeSG "ClickFix" social engineering campaign. The attack begins with a fake verification page that tricks users into executing malicious commands, leading to the deployment of an unidentified Remote Access Trojan (RAT) on the target Windows host.
The infection further escalates as the unidentified RAT installs MeshAgent, a legitimate remote management tool leveraged by attackers for persistent access. The analysis provides associated IOCs, packet captures, and malware samples, alongside screenshots of the malicious Mesh C2 console and the persistent components residing within the user's local directory.
Top comments (0)