SmartApeSG

Aliases: HANEYMANEY, ZPHP

Malware type
rat, credential-stealer, downloader
Family
Malware family
Last IoC activity
2026-07-22 04:29:15
Profile updated
2026-07-07 14:34:28

Targeted industries: government-and-public-sector financial-services healthcare-and-pharmaceutical technology-and-telecommunications

Context

According to Proofpoint, this is a cluster of fake update campaigns delivering payloads like NetSupportManager RAT and Lumma Stealer.

Detection coverage

  • 1 YARA rules

Detection rules

  • RUSSIANPANDA_Smartapesg_JS_Netsupportrat_Stage2 (yara-rule)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Js.Smartapesg (report)
  • esentire.com — Smartapesg Delivering Netsupport Rat (report)
  • proofpoint.com — Are You Sure Your Browser Date Current Landscape Fake Browser Updates (report)
  • isc.sans.edu — 32474 (report)
  • medium.com — Smartapesg 4605157A5B80 (report)
  • team-cymru.com — Tracing The Path From Smartapesg To Netsupport Rat (report)
  • threatdown.com — Smartapesg 06 11 2024 (report)

External references