SmartApeSG campaign pushes Remcos RAT, NetSupport RAT, StealC, and Sectop RAT (ArechClient2), (Wed, Mar 25th)

2026-03-25T01:23:46Z530c4413f0462e929dfc63c7b3d029b54d67aaf1b40b6138fdedc4f4e243bbfc
ArechClient2DShieldGSocketIP KVMKVM vulnerabilitiesNetSupportRATRemcosSectopSmartApeSGStealCadminerbackdoorbashcampaigncowriehoneypotmalwarephpmyadminrogue devicescanningtelemetrythreat-intel

What happened

SANS ISC diary entries (Mar 18–25, 2026) cover several active threats and telemetry: a SmartApeSG campaign distributing multiple remote access Trojans (Remcos RAT, NetSupport RAT, StealC, and Sectop/ArechClient2); discovery of a Bash script that installs a GSocket backdoor; ongoing scans and honeypot telemetry (cowrie/DShield) including an "iranbot" marker and widespread scans for adminer/phpmyadmin; discussion of IP KVM vulnerabilities and risks from rogue IP KVM devices; and routine tool/security updates and daily Stormcast podcast posts. Content is primarily operational telemetry, IoCs andT

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
530c4413f0462e929dfc63c7b3d029b54d67aaf1b40b6138fdedc4f4e243bbfc
Enrichment time
2026-03-25T01:23:46Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.