NOTICE:
ASSOCIATED FILES:

Shown above: Screenshot of SmartApeSG fake verification page.

Shown above: Screenshot of SmartApeSG fake verification page with ClickFix instructions.

Shown above: ClickFix text from the fake verification page.

Shown above: Traffic from the infection filtered in Wireshark.

Shown above: Unidentified RAT persistent on an infected Windows host.

Shown above: MeshAgent persistent on an infected Windows host.

Shown above: MeshAgent files running on an infected Windoes host in the AppData\Local\Temp directory.

Shown above: Login console from the malicious Mesh C2 server.
Click here to return to the main page.