SmartApeSG campaign uses ClickFix page to push Remcos RAT, (Sat, Mar 14th)
2026-03-14T19:23:46Z•2a921f21773868e1367086add3dc723147cad53b4de25b3bb230e18225f1899a
CVE-2026-0866ChromiumEdgeEmailJSEncrypted Client HelloIoTMicrosoft Patch TuesdayRFCReactRemcosSmartApeSGTLSZombie Zipcredential theftdefault credentialspatchingphishingthreat campaignvulnerabilities
What happened
SANS ISC diary entries (Mar 9–14, 2026) cover multiple active threats and notable security news: a SmartApeSG campaign using a ClickFix page to deliver the Remcos RAT; a React-based phishing page that exfiltrates credentials via the legitimate EmailJS service; publication of the "Zombie Zip" vulnerability (CVE-2026-0866); Microsoft Patch Tuesday (Mar 2026) addressing 93 vulnerabilities including 8 rated critical and 9 Chromium issues affecting Edge; risks from IoT devices that log in as admin; and discussion of Encrypted Client Hello RFCs. Several items describe active credential theft and RAT
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- 2a921f21773868e1367086add3dc723147cad53b4de25b3bb230e18225f1899a
- Enrichment time
- 2026-03-14T19:23:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.