SmartApeSG is a malware delivery threat actor tracked under the aliases ZPHP and HANEYMANEY. The actor is known for social-engineering-driven delivery chains that rely heavily on ClickFix lures, fake CAPTCHA or human-verification pages, fake browser updates, and malicious script injection into compromised legitimate websites. In 2026, SmartApeSG was also linked to a supply-chain compromise involving malicious JavaScript injected into the Okendo Reviews widget, exposing downstream e-commerce sites to staged malware delivery. The actor’s operations are primarily Windows-focused and are designed to trick victims into manually executing clipboard-injected commands through the Windows Run dialog, after which PowerShell scripts or HTA downloaders retrieve additional payloads. SmartApeSG commonly uses staged JavaScript loaders with execution control and evasion features, including localStorage-based suppression of repeat execution, User-Agent filtering to prioritize desktop victims, runtime reconstruction of hidden next-stage infrastructure, and dynamic script loading. Across observed campaigns, the actor has delivered multiple malware families, including NetSupport RAT, Remcos RAT, StealC, and Sectop RAT. Delivery chains have included JavaScript-in-ZIP archives, Base64-decoded payload retrieval, HTA downloaders, password-protected ZIP archives, and abuse of legitimate executables for DLL side-loading. SmartApeSG has also abused legitimate remote administration software, particularly NetSupport Manager, by configuring it for attacker-controlled access. Post-compromise behavior associated with SmartApeSG includes remote access, credential theft through stealer malware, keylogging-capable RAT deployment, persistence via Windows Run entries and scheduled tasks, and encrypted or encoded command-and-control communications. Multiple campaigns showed multi-stage infections in which several malware families were deployed sequentially on the same host over hours. The actor has demonstrated flexibility in payload selection and infrastructure rotation while maintaining consistent tradecraft centered on user-assisted execution, compromised web assets, and modular follow-on malware delivery. Available evidence supports classification of SmartApeSG as a financially motivated cybercrime threat actor rather than a state-sponsored espionage group.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
34 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 malware families attributed to this actor across reporting.
1 additional family tracked in Mallory.
71 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting a ClickFix campaign that leads victims to a fake CAPTCHA/human verification page, uses clipboard-injected text executed via the Run dialog, downloads an HTA file and ZIP archive, and ultimately deploys an unidentified RAT using DLL side-loading.
Conducted a supply chain attack by injecting malicious JavaScript into the Okendo Reviews widget to deliver malware to visitors of e-commerce websites. The campaign used staged JavaScript loading and social engineering to install remote access tools and information stealers on victim systems.
Conducted a supply chain attack via the Okendo Reviews widget by injecting staged malicious JavaScript into a widely used third-party e-commerce component. The loader used obfuscation, environment checks, staged retrieval, and ClickFix-style social engineering to deliver follow-on malware including RATs and information stealers.
Uses injected JavaScript as a staged loader to control execution, reconstruct hidden infrastructure, retrieve follow-on payloads, and support ClickFix-style infection chains that present fake CAPTCHA/verification prompts, instruct users to run copied commands via the Windows Run menu, retrieve PowerShell or HTA downloaders, and deploy remote access tools or information stealers.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.