2026-09-15 (TUESDAY): SMARTAPESG CLICKFIX TO UNIDENTIFIED RAT TO MESHAGENT

NOTICE:

ASSOCIATED FILES:

 

IMAGES


Shown above: Screenshot of SmartApeSG fake verification page.

 


Shown above: Screenshot of SmartApeSG fake verification page with ClickFix instructions.

 


Shown above: ClickFix text from the fake verification page.

 


Shown above: Traffic from the infection filtered in Wireshark.

 


Shown above: Unidentified RAT persistent on an infected Windows host.

 


Shown above: MeshAgent persistent on an infected Windows host.

 


Shown above: MeshAgent files running on an infected Windoes host in the AppData\Local\Temp directory.

 


Shown above: Login console from the malicious Mesh C2 server.

 

Click here to return to the main page.