SmartApeSG is a malware delivery threat cluster known for ClickFix-style social engineering that uses fake CAPTCHA or human-verification prompts to trick users into executing attacker-supplied commands through the Windows Run dialog. The actor is also tracked as ZPHP and HANEYMANEY. Operations commonly begin with malicious JavaScript injected into compromised legitimate websites or third-party web components, including a documented supply-chain compromise of the Okendo Reviews widget. The injected code acts as a staged loader, using execution guards such as localStorage checks, desktop-focused User-Agent filtering, obfuscated string reconstruction, and dynamic script loading to selectively deliver later stages while reducing visibility. SmartApeSG has been associated with delivery of multiple malware families, including Remcos RAT, NetSupport RAT, StealC, Sectop RAT, and additional unidentified remote access trojans. Observed infection chains frequently rely on PowerShell or HTA downloaders, password-protected archives, and abuse of legitimate executables for DLL side-loading. In documented cases, the actor has established persistence on Windows systems through Registry modifications and scheduled tasks. Campaigns have also shown multi-stage post-exploitation delivery, with several malware families deployed sequentially on a single host. The actor’s tradecraft emphasizes social engineering, malware staging, and flexible payload delivery rather than a single exclusive malware family. Activity has been observed across compromised websites and high-traffic e-commerce environments, creating broad downstream exposure. The use of remote access trojans and information stealers, combined with repeated desktop-focused ClickFix workflows, indicates an intrusion model centered on initial access, persistence, credential and data theft, and sustained control of victim systems. No high-confidence attribution to a nation state is established in the available facts.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
33 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 malware families attributed to this actor across reporting.
1 additional family tracked in Mallory.
68 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting a ClickFix campaign that leads victims to a fake CAPTCHA/human verification page, uses clipboard-injected text executed via the Run dialog, downloads an HTA file and ZIP archive, and ultimately deploys an unidentified RAT using DLL side-loading.
Conducted a supply chain attack by injecting malicious JavaScript into the Okendo Reviews widget to deliver malware to visitors of e-commerce websites. The campaign used staged JavaScript loading and social engineering to install remote access tools and information stealers on victim systems.
Conducted a supply chain attack via the Okendo Reviews widget by injecting staged malicious JavaScript into a widely used third-party e-commerce component. The loader used obfuscation, environment checks, staged retrieval, and ClickFix-style social engineering to deliver follow-on malware including RATs and information stealers.
Uses injected JavaScript as a staged loader to control execution, reconstruct hidden infrastructure, retrieve follow-on payloads, and support ClickFix-style infection chains that present fake CAPTCHA/verification prompts, instruct users to run copied commands via the Windows Run menu, retrieve PowerShell or HTA downloaders, and deploy remote access tools or information stealers.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.