Threadlinqs IntelligenceStart free

Threat actorRussiaTracked since 2026-03

SmartApeSG

Also known as:ZPHPHANEYMANEY

As of 2026-08-21, SmartApeSG is a Russia-nexus threat actor tracked by Threadlinqs Intelligence across 4 threats spanning malware. Also known as ZPHP, HANEYMANEY. ATT&CK coverage spans 47 techniques across 11 tactics in 4 of 4 tracked threats. Most-observed techniques: T1027 (Obfuscated Files or Information), T1036 (Masquerading), T1071 (Application Layer Protocol).

Tracked threats
43 high · 1 medium
First seen
2026-03-13
Last seen
2026-08-21
ATT&CK techniques
47across 4 of 4 threats
Related CVEs
0None referenced
Attribution
RussiaNation or origin
Nation: Russia · 4 tracked threat(s) · Categories: MALWARE

Activity timeline

SmartApeSG appears in 4 tracked threats between and ; the busiest month was 2026-03 with 1 report.

ATT&CK techniques observed

47 techniques observed across 4 of 4 tracked threats · Stealth (formerly Defense Evasion) (11), Command and Control (10), Collection (5), Execution (5), Persistence (4), Discovery (3)
  • T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 4 of 4 tracked threats
  • T1036 Masquerading — Stealth (formerly Defense Evasion)observed in 3 of 4 tracked threats
  • T1071 Application Layer Protocol — Command and Controlobserved in 3 of 4 tracked threats
  • T1105 Ingress Tool Transfer — Command and Controlobserved in 3 of 4 tracked threats
  • T1140 Deobfuscate/Decode Files or Information — Stealth (formerly Defense Evasion)observed in 3 of 4 tracked threats
  • T1189 Drive-by Compromise — Initial Accessobserved in 3 of 4 tracked threats
  • T1547 Boot or Logon Autostart Execution — Persistenceobserved in 3 of 4 tracked threats
  • T1041 Exfiltration Over C2 Channel — Exfiltrationobserved in 2 of 4 tracked threats
  • T1059 Command and Scripting Interpreter — Executionobserved in 2 of 4 tracked threats
  • T1070 Indicator Removal — Stealth (formerly Defense Evasion)observed in 2 of 4 tracked threats
  • T1082 System Information Discovery — Discoveryobserved in 2 of 4 tracked threats
  • T1113 Screen Capture — Collectionobserved in 2 of 4 tracked threats
  • T1132 Data Encoding — Command and Controlobserved in 2 of 4 tracked threats
  • T1204 User Execution — Executionobserved in 2 of 4 tracked threats
  • T1218 System Binary Proxy Execution — Stealth (formerly Defense Evasion)observed in 2 of 4 tracked threats

Tracked threats