SmartApeSG campaign uses ClickFix page to push Remcos RAT, (Sat, Mar 14th)

2026-03-14T07:23:45Z4f499121e8fe291f1adfb90a6576ed7c9e764668e0e015967c8279abdcaf7139
ChromiumClickFixEdgeEmailJSEncrypted Client HelloIoTMicrosoft Patch TuesdayRATRFCReactRemcosSmartApeSGZombie Zipcredential-exfiltrationdefault-adminphishingvulnerability

What happened

Multiple ISC diary entries cover active malware and phishing campaigns, a newly published vulnerability, and broad Microsoft updates. Notable items: a SmartApeSG campaign using a ClickFix-themed page to deliver the Remcos RAT; a React-based phishing page that exfiltrates credentials via the legitimate EmailJS service; publication and analysis of the “Zombie Zip” vulnerability (CVE-2026-0866); Microsoft Patch Tuesday addressing 93 flaws (including 9 Chromium/Edge issues and several critical bugs); and additional notes on IoT devices defaulting to admin credentials and RFCs for Encrypted Client‑

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
4f499121e8fe291f1adfb90a6576ed7c9e764668e0e015967c8279abdcaf7139
Enrichment time
2026-03-14T07:23:45Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.