SmartApeSG campaign uses ClickFix page to push Remcos RAT, (Sat, Mar 14th)
2026-03-15T07:23:48Z•a686f0f9e54cc97905e64fedea76e02d74ba268e11c0f0081855e903c8138b31
CVE-2026-0866ChromiumClickFixECHEdgeEmailJSEncrypted Client HelloIoTMicrosoft Patch TuesdayRATRFCReactRemcosSANS-ISCSmartApeSGZombie Zipadmin-logincredential-theftcritical-vulnerabilitiesphishingpodcast
What happened
SANS ISC diary (Mar 9–14, 2026) reports multiple security items: a SmartApeSG campaign using a ClickFix page to distribute the Remcos RAT; a React-based phishing page that exfiltrates credentials via the legitimate EmailJS service; publication of the "Zombie Zip" vulnerability (CVE-2026-0866); Microsoft Patch Tuesday (Mar 2026) with fixes for 93 vulnerabilities including 8 rated critical and multiple Chromium/Edge issues; discussion of Encrypted Client Hello (ECH) RFCs and an IoT guest diary about devices exposing admin logins. Source: ISC SANS diary posts and podcasts.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- a686f0f9e54cc97905e64fedea76e02d74ba268e11c0f0081855e903c8138b31
- Enrichment time
- 2026-03-15T07:23:48Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.