SmartApeSG campaign pushes Remcos RAT, NetSupport RAT, StealC, and Sectop RAT (ArechClient2), (Wed, Mar 25th)
2026-03-25T19:23:52Z•3cfaf0b4173e7171f94eb10f764b57db1be2897f8078fbde8b0c86248b00751c
arechclient2backdoorcowrieeclypsiumgSockethoneypot-logsioc-ip-64.89.161.198ip-kvmmalicious-bashmalware-campaignnetsupport-ratremcossans-iscsectopstealctelnet-compromisethreat-intel
What happened
SANS ISC diary roundup (Mar 18–25, 2026) highlighting a SmartApeSG malware campaign delivering multiple RATs (Remcos, NetSupport RAT, StealC, and Sectop/ArechClient2), a malicious Bash script that installs a GSocket backdoor, and honeypot/cowrie logs showing successful Telnet access and an embedded message tied to activity from IP 64.89.161.198. Also notes on IP KVM security and rogue IP KVM risks (referencing Eclypsium reporting), routine tool/security fixes, and daily Stormcast podcast entries. No specific CVEs are referenced in the entries.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- 3cfaf0b4173e7171f94eb10f764b57db1be2897f8078fbde8b0c86248b00751c
- Enrichment time
- 2026-03-25T19:23:52Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.