SmartApeSG Campaign Deploys Multiple RATs and Data Stealer

SmartApeSG used a fake‑CAPTCHA ClickFix page to deliver Remcos RAT. Operators then staged NetSupport RAT, StealC stealer, and Sectop (ArechClient2) as follow‑on payloads. Follow‑on components appeared in intervals from minutes to over an hour after initial compromise.

Part of the PlainSec briefing for 2026-03-26

Sources