SmartApeSG campaign uses ClickFix page to push Remcos RAT, (Sat, Mar 14th)
2026-03-14T07:23:45Z•4f499121e8fe291f1adfb90a6576ed7c9e764668e0e015967c8279abdcaf7139
ChromiumClickFixEdgeEmailJSEncrypted Client HelloIoTMicrosoft Patch TuesdayRATRFCReactRemcosSmartApeSGZombie Zipcredential-exfiltrationdefault-adminphishingvulnerability
What happened
Multiple ISC diary entries cover active malware and phishing campaigns, a newly published vulnerability, and broad Microsoft updates. Notable items: a SmartApeSG campaign using a ClickFix-themed page to deliver the Remcos RAT; a React-based phishing page that exfiltrates credentials via the legitimate EmailJS service; publication and analysis of the “Zombie Zip” vulnerability (CVE-2026-0866); Microsoft Patch Tuesday addressing 93 flaws (including 9 Chromium/Edge issues and several critical bugs); and additional notes on IoT devices defaulting to admin credentials and RFCs for Encrypted Client‑
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- 4f499121e8fe291f1adfb90a6576ed7c9e764668e0e015967c8279abdcaf7139
- Enrichment time
- 2026-03-14T07:23:45Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.