A sophisticated malware campaign attributed to the SmartApeSG threat actor (also tracked as ZPHP/HANEYMANEY) has targeted users through compromised websites since early 2024, deploying NetSupport RAT and StealC malware via fraudulent browser update notifications.
The campaign exemplifies the growing sophistication of social engineering tactics combined with advanced evasion techniques like DLL side-loading.
“Legitimate but compromised websites with an injected script for #SmartApeSG lead to a fake browser update page that distributes #NetSupportRAT malware. During an infection run, we saw follow-up malware for #StealC.” Unit 42 researchers said.
Cyber Security News have conducted an in-depth analysis of fake browser updates, providing a detailed technical examination of this campaign.
Initially SmartApeSG injects malicious JavaScript into vulnerable websites, typically those running outdated WordPress or content management systems.
Visitors to these sites encounter pop-ups mimicking legitimate browser update prompts for Chrome, Edge, or Firefox (Figure 1). These lures leverage realistic branding and urgency warnings, such as “Critical Security Update Required”.
The JavaScript, often obfuscated or hidden within legitimate code blocks, redirects users to attacker-controlled domains like cinaweine[.]shop or poormet[.]com.
These domains host malicious payloads disguised as browser installers, including Update_browser_17.6436.js or Update 7673.js.
Upon executing the downloaded JavaScript, a PowerShell script decodes Base64-encoded commands to fetch a ZIP archive containing NetSupport RAT components.
The archive (lol.zip) includes:
NetSupport RAT establishes connections to command-and-control (C2) servers like sdjfnvnbbz[.]pw or 194.180.191[.]229, enabling threat actors to:
In recent campaigns observed on February 18, 2025, NetSupport RAT delivered a secondary payload: StealC, a credential-stealing malware.
The attackers utilized DLL side-loading to execute StealC by abusing mfpmp.exe, a legitimate Windows Media Foundation file. The malicious rtworkq.dll (725 MB, inflated to evade detection) was loaded to harvest:
Data exfiltration occurred via HTTP POST requests to domains like 62.164.130[.]69, which hosted decoy DLLs (sqlite3.dll, nss3.dll) to blend with legitimate traffic.
SmartApeSG exploited Windows’ DLL search order by placing malicious libraries alongside legitimate executables. For example:
This technique, documented in MITRE ATT&CK (T1574.002), allows attackers to masquerade malicious activity under trusted processes like Windows utilities or media players.
SmartApeSG operates within a crowded ecosystem of threat actors using fake browser updates, including:
Proofpoint researchers note that over 80% of these campaigns lead to remote access trojans (RATs) or initial access brokers for ransomware groups.
The SmartApeSG campaign underscores the persistent threat of social engineering coupled with fileless attack techniques.
By exploiting trusted software update mechanisms and Windows internals, threat actors achieve prolonged network access while evading conventional defenses.
Organizations must adopt layered defenses combining endpoint detection, network segmentation, and user awareness—to mitigate risks from evolving RAT-based campaigns.
Free Webinar: Better SOC with Interactive Malware Sandbox for Incident Response, and Threat Hunting – Register Here
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…