Security researchers linked SmartApeSG to an intrusion chain that used a compromised website to serve a fake browser update ZIP, leading victims to execute a malicious JavaScript file. The script retrieved additional payloads from attacker-controlled URLs, including Base64-encoded content that was decoded into a ZIP archive containing NetSupport RAT components, after which client32.exe was launched on the victim system.
The activity was detected during a January 2024 incident when eSentire's BlueSteel PowerShell classifier flagged malicious PowerShell execution. Investigators said the malware established persistence through the Windows Run registry key, confirming a full remote-access trojan deployment tied to SmartApeSG. eSentire reported that it isolated the affected host, contained the intrusion, and notified the customer.

Pull IOCs and campaign context straight into your stack.
3 events from the most recent confirmed update back to the earliest known activity.
After confirming the activity was malicious, eSentire used its MDR for Endpoint capability to isolate the affected host. The company said it contained the threat and notified the customer of the suspicious activity.
The compromised webpage delivered a fake browser update ZIP containing a JavaScript file that fetched additional payloads, launched PowerShell, downloaded Base64-encoded content, extracted a ZIP archive, executed client32.exe, and established Run-key persistence. The decoded archive contained NetSupport RAT components, including the client.
In early January 2024, eSentire's BlueSteel PowerShell classifier detected malicious PowerShell execution on a customer host. eSentire's Threat Response Unit attributed the activity to SmartApeSG and traced it to a user visiting a compromised webpage serving a fake browser update.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.