SmartApeSG campaign uses ClickFix page to push Remcos RAT, (Sat, Mar 14th)
2026-03-14T13:23:48Z•e05271da2998feca59ad5878b0e2c1c33912cb12a44c50c137a540b2aa8aa3de
CVE-2026-0866ChromiumClickFixEdgeEmailJSEncrypted Client HelloIoTMicrosoft Patch TuesdayRATReactRemcosSmartApeSGZombie-Zipcredential-theftcritical-vulnerabilitiesphishing
What happened
Collection of SANS ISC diary entries (Mar 9–14, 2026): A SmartApeSG campaign abused a ClickFix page to distribute the Remcos RAT; a React-based phishing page used the legitimate EmailJS service to exfiltrate credentials; a new vulnerability dubbed “Zombie Zip” was published as CVE-2026-0866; Microsoft’s March 2026 Patch Tuesday fixed 93 vulnerabilities (including 8 rated critical and 9 Chromium vulnerabilities affecting Edge). Other items include IoT device admin-login warnings and discussion of Encrypted Client Hello RFCs, plus regular ISC Stormcast podcast entries.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- e05271da2998feca59ad5878b0e2c1c33912cb12a44c50c137a540b2aa8aa3de
- Enrichment time
- 2026-03-14T13:23:48Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.