SmartApeSG campaign uses ClickFix page to push Remcos RAT, (Sat, Mar 14th)

2026-03-14T13:23:48Ze05271da2998feca59ad5878b0e2c1c33912cb12a44c50c137a540b2aa8aa3de
CVE-2026-0866ChromiumClickFixEdgeEmailJSEncrypted Client HelloIoTMicrosoft Patch TuesdayRATReactRemcosSmartApeSGZombie-Zipcredential-theftcritical-vulnerabilitiesphishing

What happened

Collection of SANS ISC diary entries (Mar 9–14, 2026): A SmartApeSG campaign abused a ClickFix page to distribute the Remcos RAT; a React-based phishing page used the legitimate EmailJS service to exfiltrate credentials; a new vulnerability dubbed “Zombie Zip” was published as CVE-2026-0866; Microsoft’s March 2026 Patch Tuesday fixed 93 vulnerabilities (including 8 rated critical and 9 Chromium vulnerabilities affecting Edge). Other items include IoT device admin-login warnings and discussion of Encrypted Client Hello RFCs, plus regular ISC Stormcast podcast entries.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
e05271da2998feca59ad5878b0e2c1c33912cb12a44c50c137a540b2aa8aa3de
Enrichment time
2026-03-14T13:23:48Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.