SmartApeSG, also tracked as ZPHP, HANEYMANEY, and smartape_sg, is a malware-distribution threat actor and campaign active since at least January 2024. Its operations use compromised legitimate websites, fake browser updates, and ClickFix social engineering to infect Windows systems. Injected JavaScript redirects visitors to fraudulent CAPTCHA or human-verification pages that place malicious commands in the clipboard and instruct users to execute them through the Windows Run dialog. Infection chains use JavaScript, PowerShell, and HTML Application downloaders to retrieve and unpack malicious archives. Delivered payloads include NetSupport RAT, Remcos RAT, StealC, Sectop RAT, and unidentified remote-access trojans. Some infections deploy several malware families sequentially on the same host, enabling remote access, credential theft, keylogging, and data exfiltration. Follow-on activity has also installed MeshAgent. The actor abuses legitimate executables for DLL side-loading and establishes persistence through registry autorun entries and scheduled tasks. Evasion techniques include script obfuscation, encoded payloads, runtime reconstruction of delivery infrastructure, selective execution based on browser characteristics, and deletion of staging artifacts. In May 2026, SmartApeSG compromised the third-party Okendo Reviews widget by injecting a staged JavaScript loader, exposing downstream e-commerce websites, including a U.S. retail brand. The loader filtered out mobile visitors, used browser-side state to suppress repeated execution, and dynamically retrieved subsequent stages leading to ClickFix prompts. Its delivery channels span mid-sized online stores and large retail websites; exposure to compromised pages does not establish that every visitor was infected. The actor's country of origin and dominant motivation are not established.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
31 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 malware families attributed to this actor across reporting.
1 additional family tracked in Mallory.
75 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
SmartApeSG is identified as using ClickFix to distribute the CNCmachineRMS remote access trojan. The provided content contains only an article title, limiting further assessment.
Used a fake verification page with ClickFix instructions to deliver an unidentified RAT and establish persistent MeshAgent remote-management access on infected Windows hosts.
Conducting a ClickFix-based malware campaign in which JavaScript injected into legitimate websites redirects victims to fake CAPTCHA pages. Victims are induced to paste a malicious command into the Windows Run dialog; this executes an HTA downloader that retrieves a ZIP archive containing an unidentified RAT. The RAT uses DLL side-loading for execution and persistence and communicates with C2 over encrypted TCP/443.
Conducting a ClickFix campaign that leads victims to a fake CAPTCHA/human verification page, uses clipboard-injected text executed via the Run dialog, downloads an HTA file and ZIP archive, and ultimately deploys an unidentified RAT using DLL side-loading.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.