Researchers documented a SmartApeSG malware campaign using fake CAPTCHA pages and the ClickFix social-engineering technique to trick victims into launching an initial script that led to a multi-stage infection. In observed intrusions, Remcos RAT executed first, followed within minutes by NetSupport RAT, then StealC, and later Sectop RAT identified as ArechClient2. The activity relied on compromised web infrastructure, rotating delivery domains, attacker-controlled command-and-control servers, and multiple payload packages, with several stages using DLL side-loading through legitimate executables while NetSupport RAT was deployed as a legitimate remote administration tool configured for malicious control.
Separate analysis tied Sectop RAT / ArechClient2 to additional follow-on infections, including a chain where a victim seeking cracked software downloaded a password-protected archive that installed Lumma Stealer before fetching a 64-bit DLL from enotsosun[.]pw and executing it via rundll32 using the LoadForm export. Investigators reported concrete indicators including malware hashes, filenames, persistence artifacts, malicious URLs, and network traffic from Sectop RAT to 91.92.241[.]102 over ports 9000 and 443, reinforcing that ArechClient2 is being used across varied delivery lures as part of broader credential theft and remote-access operations.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
On 2026-05-27, a SmartApeSG ClickFix infection chain was observed delivering an unidentified initial RAT that communicated with 89.110.110[.]119:443, followed by a malicious NetSupport Manager RAT package communicating with 185.163.47[.]217:443. The report identified lure and delivery infrastructure including hiddenplanetlab[.]top and silverharvestnetwork[.]com, plus installation and persistence files such as processor.vbs, token.bat, and setup.cab under C:\ProgramData.
A separate malware infection chain was documented in which a user searching for cracked software downloaded a password-protected archive that installed Lumma Stealer, followed by a Sectop RAT (ArechClient2) DLL executed via rundll32. The report included C2 domains, malicious URLs, hashes, persistence details, and network traffic to 91.92.241[.]102 over ports 9000 and 443.
VMRay released a report focused on ArechClient2 SectopRAT, adding technical analysis of this malware family and its behavior. The reference indicates public reporting on the malware by March 31, 2026.
On March 24, 2026, Bradley Duncan documented a SmartApeSG infection in which a victim executing a ClickFix script received Remcos RAT first, then NetSupport RAT, followed by StealC and finally Sectop RAT (ArechClient2). The analysis also identified delivery infrastructure, C2 servers, hashes, and use of DLL side-loading for several payloads.
A SmartApeSG campaign was observed using a fake CAPTCHA ClickFix page to infect victims and deliver Remcos RAT. Malware-Traffic-Analysis.net published supporting sample files for this infection chain tied to activity dated March 12, 2026.
An earlier SANS ISC diary reported SmartApeSG using a ClickFix page to deliver NetSupport RAT, showing the campaign had already been using fake CAPTCHA lures before the March 2026 multi-malware chain. The exact activity date is not provided in the reference, so the publication date is used.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourceisc.sans.edu
Open sourceisc.sans.edu
Open sourceisc.sans.edu
Open sourceisc.sans.edu
Open sourcemalware-traffic-analysis.net
Open sourceisc.sans.edu
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.