SmartApeSG campaign pushes Remcos RAT, NetSupport RAT, StealC, and Sectop RAT (ArechClient2), (Wed, Mar 25th)
2026-03-25T01:23:46Z•530c4413f0462e929dfc63c7b3d029b54d67aaf1b40b6138fdedc4f4e243bbfc
ArechClient2DShieldGSocketIP KVMKVM vulnerabilitiesNetSupportRATRemcosSectopSmartApeSGStealCadminerbackdoorbashcampaigncowriehoneypotmalwarephpmyadminrogue devicescanningtelemetrythreat-intel
What happened
SANS ISC diary entries (Mar 18–25, 2026) cover several active threats and telemetry: a SmartApeSG campaign distributing multiple remote access Trojans (Remcos RAT, NetSupport RAT, StealC, and Sectop/ArechClient2); discovery of a Bash script that installs a GSocket backdoor; ongoing scans and honeypot telemetry (cowrie/DShield) including an "iranbot" marker and widespread scans for adminer/phpmyadmin; discussion of IP KVM vulnerabilities and risks from rogue IP KVM devices; and routine tool/security updates and daily Stormcast podcast posts. Content is primarily operational telemetry, IoCs andT
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- 530c4413f0462e929dfc63c7b3d029b54d67aaf1b40b6138fdedc4f4e243bbfc
- Enrichment time
- 2026-03-25T01:23:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.