SmartApeSG campaign uses ClickFix page to push Remcos RAT, (Sat, Mar 14th)

2026-03-15T01:23:46Zf94ee2fe0b8d75c3b2d1e0555f92964e5052f87abd4b2d8e0c4953b0181b75bc
CVE-2026-0866chromiumclickfixcredential-theftechedgeemailjsiot-default-credentialsmicrosoft-patch-tuesdayphishingratreactjsremcosrfczombie-zip

What happened

SANS ISC Diary entries (Mar 9–14, 2026) highlight multiple active threats and notable advisories: a SmartApeSG campaign abusing a ClickFix page to deliver the Remcos RAT; a sophisticated React-based phishing page that exfiltrates credentials via the legitimate EmailJS service; publication/analysis of the “Zombie Zip” vulnerability (CVE-2026-0866); Microsoft’s March 2026 Patch Tuesday addressing 93 vulnerabilities (including 8 rated critical and multiple Chromium/Edge bugs); warnings about IoT devices logging in as admin (default/weak credentials); and discussion of recently published Encrypted

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
f94ee2fe0b8d75c3b2d1e0555f92964e5052f87abd4b2d8e0c4953b0181b75bc
Enrichment time
2026-03-15T01:23:46Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.