#SecTop
2025-07-15 (Tuesday): #LummaStealer infection with #SecTopRAT. A #pcap of the #Lumma traffic and #SecTop #RAT activity, the #malware / artifacts from an infection, and the associated IOCs are available at www.malware-traffic-analysis.net/2025/07/15/i...
July 16, 2025 at 2:13 AM
1/ Today, Insikt Group is publishing on GrayCharlie, a threat actor active since mid-2023 that overlaps with SmartApeSG. GrayCharlie compromises WordPress sites and turns them into malware delivery hubs: www.recordedfuture.com/research/gra...
GrayCharlie Hijacks Law Firm Sites in Suspected Supply-Chain Attack
GrayCharlie turns compromised WordPress sites into malware delivery machines. Discover how this threat actor chains fake browser updates and ClickFix lures to deploy NetSupport RAT, Stealc, and Sectop...
www.recordedfuture.com
February 18, 2026 at 5:13 PM
SANS Stormcast Monday, April 20th, 2026: Lumma Stealer and Sectop RAT; Windows 0-Day Exploited; NIST NVD Update; FortiSandbox PoC
https://isc.sans.edu/podcastdetail/9898
April 20, 2026 at 2:01 AM
8/ Read the full report for technical details, infrastructure analysis, and defensive guidance: www.recordedfuture.com/research/gra...
GrayCharlie Hijacks Law Firm Sites in Suspected Supply-Chain Attack
GrayCharlie turns compromised WordPress sites into malware delivery machines. Discover how this threat actor chains fake browser updates and ClickFix lures to deploy NetSupport RAT, Stealc, and Sectop...
www.recordedfuture.com
February 18, 2026 at 5:13 PM
GrayCharlie、サプライチェーン攻撃とみられる法律事務所サイトを乗っ取る
#CybersecurityNews
www.recordedfuture.com/research/gra...
GrayCharlie Hijacks Law Firm Sites in Suspected Supply-Chain Attack
GrayCharlie turns compromised WordPress sites into malware delivery machines. Discover how this threat actor chains fake browser updates and ClickFix lures to deploy NetSupport RAT, Stealc, and Sectop...
www.recordedfuture.com
March 2, 2026 at 8:00 AM
SmartApeSG injected malicious JavaScript into the Okendo Reviews widget, turning a trusted e-commerce plugin into a supply-chain delivery path for malware loaders and RATs. #SmartApeSG #OkendoReviews #SupplyChain
SmartApeSG Launches Okendo Reviews Supply Chain Attack
ThreatLabz found SmartApeSG injecting malicious JavaScript into the Okendo Reviews widget, creating a supply-chain style compromise that could affect many high-traffic e-commerce sites. The loader used obfuscation, environment checks, staged retrieval, and ClickFix-style prompts to support follow-on delivery of tools such as NetSupport, Remcos, StealC, and Sectop RAT. #SmartApeSG #OkendoReviews #NetSupport #Remcos #StealC #SectopRAT
www.hendryadrian.com
June 18, 2026 at 11:45 PM
Claude Desktop偽インストーラー、DLLサイドローディングとブロックチェーンC2でSectopRATを展開

Claude Desktopの偽インストーラーを使ったキャンペーンが確認されました。Bingの不正広告を悪用して信頼されているClaude.aiがホストするコンテンツになりすまし、DLLサイドローディングとブロックチェーンベースのコマンド&コントロール(C2)を組み合わせて、リモートアクセス型トロイの木馬Sectop...
Claude Desktop偽インストーラー、DLLサイドローディングとブロックチェーンC2でSectopRATを展開
Claude Desktopの偽インストーラーを使ったキャンペーンが確認されました。Bingの不正広告を悪用して信頼されているClaude.aiがホストするコンテンツになりすまし、DLLサイドローディングとブロックチェーンベースのコマンド&コントロール(C2)を組み合わせて、リモートアクセス型トロイの木馬Sectop
blackhatnews.tokyo
August 26, 2026 at 12:31 PM
Active Windows 0-day in the wild, Lumma Stealer chains with Sectop RAT, and NIST scrambles to keep up with CVE explosion. Your SOC needs to be watching this.

https://isc.sans.edu/podcastdetail/9898

#cybersecurity #infosec
April 21, 2026 at 11:30 AM
SmartApeSG ClickFix Campaign Delivers Remcos, NetSupport RAT, StealC and Sectop RAT
SmartApeSG ClickFix Campaign Delivers Remcos, NetSupport RAT, StealC and Sectop RAT
A threat campaign known as SmartApeSG — also tracked under the names ZPHP and HANEYMANEY — has been observed pushing multiple strains of malware through a social engineering technique called ClickFix. The campaign, active as recently as March 24, 2026, delivered four separate malware payloads to a single infected host in one session: Remcos RAT, NetSupport RAT, StealC, and Sectop RAT, also known as ArechClient2. This wave of activity shows how attackers stack multiple tools inside one campaign to maximize damage from a single user mistake. SmartApeSG works by injecting malicious scripts into legitimate but already-compromised websites. When a user visits one of these sites, they are redirected to a fake CAPTCHA page — a page that looks like a routine verification check but is designed to trick the user into running a harmful script. Fake CAPTCHA page (Source – Internet Storm Center) The compromised website silently loads the injected script in the background, setting up the deceptive page that the visitor encounters. Internet Storm Center researchers identified this latest SmartApeSG wave on March 24, 2026, documenting how the campaign delivered each payload in a staged sequence over several hours. The fake CAPTCHA page carries ClickFix instructions that silently copy a malicious script into the user’s clipboard, prompting the victim to paste and execute it manually through the Windows Run dialog box. Once the user follows those steps, the infection chain kicks off and runs without obvious warning signs on the compromised machine. The impact of this campaign is serious because it does not stop at one malware family. Starting at 17:12 UTC, Remcos RAT traffic was detected just one minute after the ClickFix script ran. NetSupport RAT followed only four minutes later. Then, roughly one hour after that, StealC began sending data to its own command-and-control server, followed by Sectop RAT approximately one hour and eighteen minutes after StealC appeared. This staggered delivery gives defenders a narrow window to catch the infection before multiple threats are already running in parallel on the same system. The overall payload mix — a keylogger-capable RAT, a remote support tool turned against users, a credential stealer, and a second RAT — makes clear that SmartApeSG is built to give attackers deep and varied access to a victim machine from a single infection event. DLL Side-Loading: How the Malware Hides in Plain Sight One of the more technically notable aspects of this campaign is how it hides harmful code inside packages that also contain legitimate software. The archive files for Remcos RAT, StealC, and Sectop RAT all rely on a technique called DLL side-loading, where a trusted and recognized executable file is used to quietly load a malicious DLL file alongside it. Since the main executable appears clean and familiar, many security tools may not immediately flag what is happening. NetSupport RAT takes a different path — it is itself a real and legitimate remote support application, but in this campaign, it has been configured to connect to an attacker-controlled server rather than a trusted one. Network traffic filtered in Wireshark reveals the distinct connections each malware strain makes to its own command-and-control server. The HTA file that starts the Remcos RAT download is pulled from  urotypos[.]com  and saved locally as  post.hta  before it runs. Critically, the ClickFix script deletes this HTA file right after executing it, making forensic investigation harder for response teams who do not catch the infection quickly. Organizations are strongly advised to block the domains  urotypos[.]com  and  fresicrto[.]top  at the DNS and firewall level, and to monitor outbound traffic toward  95.142.45[.]231 ,  185.163.47[.]220 ,  89.46.38[.]100 , and  195.85.115[.]11 . Employees should be trained to never paste or run clipboard content prompted by any website. Security teams should also watch for unexpected HTA file execution and unusual DLL loading activity within user-accessible directories such as AppData and ProgramData. Follow us on  Google News ,  LinkedIn , and  X  to Get More Instant Updates ,  Set CSN as a Preferred Source in  Google . The post SmartApeSG ClickFix Campaign Delivers Remcos, NetSupport RAT, StealC and Sectop RAT appeared first on Cyber Security News .
cybersecuritynews.com
March 25, 2026 at 4:32 PM
Lumma Stealer infection with Sectop RAT (ArechClient2), (Fri, Apr 17th)
#hackernews #news
Lumma Stealer infection with Sectop RAT (ArechClient2), (Fri, Apr 17th)
isc.sans.edu
April 17, 2026 at 9:39 PM
SmartApeSG campaign pushes Remcos RAT, NetSupport RAT, StealC, and Sectop RAT (ArechClient2), (Wed, Mar 25th)
#hackernews #news
SmartApeSG campaign pushes Remcos RAT, NetSupport RAT, StealC, and Sectop RAT (ArechClient2), (Wed, Mar 25th)
isc.sans.edu
March 25, 2026 at 10:25 PM
Lumma Stealer Infection Escalates Into Sectop RAT: A Deep Dive Into a Multi-Stage Malware Trap

Introduction Cybercriminals are constantly refining their methods, blending social engineering with technical evasion to compromise unsuspecting users. One of the most effective entry points remains…
Lumma Stealer Infection Escalates Into Sectop RAT: A Deep Dive Into a Multi-Stage Malware Trap
Introduction Cybercriminals are constantly refining their methods, blending social engineering with technical evasion to compromise unsuspecting users. One of the most effective entry points remains deceptively simple: cracked software downloads. What appears to be a free version of a premium tool often hides a far more costly consequence. This case highlights a real-world infection chain where Lumma Stealer acts as the initial payload, followed by the deployment of Sectop RAT (ArechClient2).
undercodenews.com
April 17, 2026 at 12:58 AM
SmartApeSG ClickFix Campaign delivers Remcos, NetSupport RAT, StealC and Sectop RAT:

cybersecuritynews.com/smartapesg-c...
March 26, 2026 at 8:42 AM
Feed: "Cyber Security News"
By: Tushar Subhra Dutta on Wednesday, March 25, 2026
SmartApeSG ClickFix Campaign Delivers Remcos, NetSupport RAT, StealC and Sectop RAT
SmartApeSG uses ClickFix on hacked sites to deliver multiple malware at once, including RATs and stealers, maximizing damage.
cybersecuritynews.com
March 26, 2026 at 4:50 AM
Feed: "GBHackers Security | #1 Globally Trusted Cyber Security News Platform"
By: Mayura Kathir on Wednesday, March 25, 2026
SmartApeSG ClickFix Campaign Spreads Remcos, NetSupport RAT, StealC, Sectop RAT
A recent SmartApeSG campaign observed on March 24, 2026, highlights the growing sophistication of ClickFix-based attack chains.
gbhackers.com
March 25, 2026 at 12:03 PM