SmartApeSG campaign uses ClickFix page to push Remcos RAT, (Sat, Mar 14th)
2026-03-15T01:23:46Z•f94ee2fe0b8d75c3b2d1e0555f92964e5052f87abd4b2d8e0c4953b0181b75bc
CVE-2026-0866chromiumclickfixcredential-theftechedgeemailjsiot-default-credentialsmicrosoft-patch-tuesdayphishingratreactjsremcosrfczombie-zip
What happened
SANS ISC Diary entries (Mar 9–14, 2026) highlight multiple active threats and notable advisories: a SmartApeSG campaign abusing a ClickFix page to deliver the Remcos RAT; a sophisticated React-based phishing page that exfiltrates credentials via the legitimate EmailJS service; publication/analysis of the “Zombie Zip” vulnerability (CVE-2026-0866); Microsoft’s March 2026 Patch Tuesday addressing 93 vulnerabilities (including 8 rated critical and multiple Chromium/Edge bugs); warnings about IoT devices logging in as admin (default/weak credentials); and discussion of recently published Encrypted
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- f94ee2fe0b8d75c3b2d1e0555f92964e5052f87abd4b2d8e0c4953b0181b75bc
- Enrichment time
- 2026-03-15T01:23:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.