threat_intelligence290 wordsRead on Arc Codex

2026-07-31: SmartApeSG ClickFix campaign pushes unidentified RAT

2026-07-31 (FRIDAY): SMARTAPESG CLICKFIX CAMPAIGN PUSHES UNIDENTIFIED RAT NOTICE: - Zip files are password-protected. Of note, this site has a new password scheme. For the password, see the "about" page of this website. ASSOCIATED FILES: - 2026-07-31-IOCs-from-SmartApeSG-activity.txt.zip 1.3 kB (1,304 bytes) - 2026-07-31-SmartApeSG-HTTPS-traffic.zip 335.8 kB (335,751 bytes) - 2026-07-31-SmartApeSG-activity.pcap.zip 18.0 MB (18,009,157 bytes) - 2026-07-31-SmartApeSG-files.zip 13.9 MB (13,946,488 bytes) 2026-07-31 (FRIDAY): SMARTAPESG CLICKFIX PUSHES UNIDENTIFIED RAT SMARTAPESG TRAFFIC LEADING TO FAKE CAPTCH/HUMAN VERIFICATION PAGE: - https[:]//pewtercanto[.]top/user/throttle-effect.js - https[:]//pewtercanto[.]top/user/throttle-effect.js - https[:]//pewtercanto[.]top/user/acl-dom?JSMlAATp - https[:]//pewtercanto[.]top/user/version-deploy.js?18c7713e5fb5a572 TRAFFIC GENERATED FROM RUNNING THE CLIPBOARD-INJECTED TEXT IN A RUN WINDOW: - hxxp[:]//deltaode[.]com/po <-- 302 redirect to HTTPS URL - hxxps[:]//deltaode[.]com/po - hxxp[:]//deltaode[.]com/wv <-- 302 redirect to HTTPS URL - hxxps[:]//deltaode[.]com/wv INITIAL HTA FILE: - SHA256 hash: e911b6bc7704a70fc60262a084813ac5ef49739ac95660d42e26c8818c044832 - File size: 39,487 bytes - File type: HTML document text, ASCII text, with very long lines (4879) - File location: hxxps[:]//deltaode[.]compo - File location: C:\Users\[username]\AppData\Local\ACER.xam - File description: HTA file used to download malicious zip archive then extract and run the content DOWNLOADED ZIP ARCHIVE: - SHA256 hash: 24f9e1a7d122d0340251828fde0a0c45f69967c14f4a1b2dfe606772bdb0b275 - File size: 13,991,507 bytes - File type: Zip archive data, at least v2.0 to extract, compression method=deflate - File location: hxxps[:]//deltaode[.]com/wv - File location: C:\Users\[username]\Documents\553003097200721800\553003097200721800.pdf - File description: File for legitimate program that uses DLL side-loading for an undentified RAT POST-INFECTION TRAFFIC FROM UNIDENTIFIED RAT: - TCP port 443 - dns[.]google - secure DNS query (not malicious) - 89.124.79[.]98 port 443 - encoded or otherwise encrypted TCP traffic to C2 server for unidentified RAT IMAGES Shown above: SmartApeSG script injected into page from legitimate but compromised website. Shown above: Fake CAPTCHA (human verification) page showing ClickFix instructions pasted into a run Window. Shown above: Traffic from the infection filtered in Wireshark. Click here to return to the main page.

How it works

Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.

Questions are cached — you'll always get the same 5 for this article.