SmartApeSG
Aliases: HANEYMANEY, ZPHP
- Malware type
- rat, credential-stealer, downloader
- Family
- Malware family
- Last IoC activity
- 2026-07-22 04:29:15
- Profile updated
- 2026-07-07 14:34:28
Targeted industries: government-and-public-sector financial-services healthcare-and-pharmaceutical technology-and-telecommunications
Context
According to Proofpoint, this is a cluster of fake update campaigns delivering payloads like NetSupportManager RAT and Lumma Stealer.
Detection coverage
- 1 YARA rules
Detection rules
- RUSSIANPANDA_Smartapesg_JS_Netsupportrat_Stage2 (yara-rule)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Js.Smartapesg (report)
- esentire.com — Smartapesg Delivering Netsupport Rat (report)
- proofpoint.com — Are You Sure Your Browser Date Current Landscape Fake Browser Updates (report)
- isc.sans.edu — 32474 (report)
- medium.com — Smartapesg 4605157A5B80 (report)
- team-cymru.com — Tracing The Path From Smartapesg To Netsupport Rat (report)
- threatdown.com — Smartapesg 06 11 2024 (report)