A sophisticated malware campaign attributed to the SmartApeSG threat actor (also tracked as ZPHP/HANEYMANEY) has targeted users through compromised websites since early 2024, deploying NetSupport RAT and StealC malware via fraudulent browser update notifications. 2025-02-18 (Tuesday): Legitimate but compromised websites with an injected script for #SmartApeSG lead to a fake browser update page that distributes #NetSupportRAT malware. “Legitimate but compromised websites with an injected script for #SmartApeSG lead to a fake browser update page that distributes #NetSupportRAT malware. Cyber Security News have conducted an in-depth analysis of fake browser updates, providing a detailed technical examination of this campaign. By exploiting trusted software update mechanisms and Windows internals, threat actors achieve prolonged network access while evading conventional defenses. Visitors to these sites encounter pop-ups mimicking legitimate browser update prompts for Chrome, Edge, or Firefox (Figure 1).
This Cyber News was published on cybersecuritynews.com. Publication date: Wed, 19 Feb 2025 18:30:08 +0000