SmartApeSG campaign uses ClickFix page to push Remcos RAT, (Sat, Mar 14th)

2026-03-14T19:23:46Z2a921f21773868e1367086add3dc723147cad53b4de25b3bb230e18225f1899a
CVE-2026-0866ChromiumEdgeEmailJSEncrypted Client HelloIoTMicrosoft Patch TuesdayRFCReactRemcosSmartApeSGTLSZombie Zipcredential theftdefault credentialspatchingphishingthreat campaignvulnerabilities

What happened

SANS ISC diary entries (Mar 9–14, 2026) cover multiple active threats and notable security news: a SmartApeSG campaign using a ClickFix page to deliver the Remcos RAT; a React-based phishing page that exfiltrates credentials via the legitimate EmailJS service; publication of the "Zombie Zip" vulnerability (CVE-2026-0866); Microsoft Patch Tuesday (Mar 2026) addressing 93 vulnerabilities including 8 rated critical and 9 Chromium issues affecting Edge; risks from IoT devices that log in as admin; and discussion of Encrypted Client Hello RFCs. Several items describe active credential theft and RAT

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
2a921f21773868e1367086add3dc723147cad53b4de25b3bb230e18225f1899a
Enrichment time
2026-03-14T19:23:46Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.