# SmartApeSG

> As of 2026-08-21, SmartApeSG is a Russia-nexus threat actor tracked by Threadlinqs Intelligence across 4 threats spanning malware. Also known as ZPHP, HANEYMANEY. ATT&CK coverage spans 47 techniques across 11 tactics in 4 of 4 tracked threats. Most-observed techniques: T1027 (Obfuscated Files or Information), T1036 (Masquerading), T1071 (Application Layer Protocol).

- **Nation:** Russia
- **Tracked threats:** 4
- **Categories:** MALWARE
- **Also known as:** ZPHP, HANEYMANEY
- **As of:** 2026-08-21

## ATT&CK techniques observed

47 techniques observed across 4 of 4 tracked threats. Tactics: Stealth (formerly Defense Evasion) (11), Command and Control (10), Collection (5), Execution (5), Persistence (4), Discovery (3).

- [T1027](https://intel.threadlinqs.com/technique/T1027) Obfuscated Files or Information — Stealth (formerly Defense Evasion) — observed in 4 of 4 tracked threats
- [T1036](https://intel.threadlinqs.com/technique/T1036) Masquerading — Stealth (formerly Defense Evasion) — observed in 3 of 4 tracked threats
- [T1071](https://intel.threadlinqs.com/technique/T1071) Application Layer Protocol — Command and Control — observed in 3 of 4 tracked threats
- [T1105](https://intel.threadlinqs.com/technique/T1105) Ingress Tool Transfer — Command and Control — observed in 3 of 4 tracked threats
- [T1140](https://intel.threadlinqs.com/technique/T1140) Deobfuscate/Decode Files or Information — Stealth (formerly Defense Evasion) — observed in 3 of 4 tracked threats
- [T1189](https://intel.threadlinqs.com/technique/T1189) Drive-by Compromise — Initial Access — observed in 3 of 4 tracked threats
- [T1547](https://intel.threadlinqs.com/technique/T1547) Boot or Logon Autostart Execution — Persistence — observed in 3 of 4 tracked threats
- [T1041](https://intel.threadlinqs.com/technique/T1041) Exfiltration Over C2 Channel — Exfiltration — observed in 2 of 4 tracked threats
- [T1059](https://intel.threadlinqs.com/technique/T1059) Command and Scripting Interpreter — Execution — observed in 2 of 4 tracked threats
- [T1070](https://intel.threadlinqs.com/technique/T1070) Indicator Removal — Stealth (formerly Defense Evasion) — observed in 2 of 4 tracked threats
- [T1082](https://intel.threadlinqs.com/technique/T1082) System Information Discovery — Discovery — observed in 2 of 4 tracked threats
- [T1113](https://intel.threadlinqs.com/technique/T1113) Screen Capture — Collection — observed in 2 of 4 tracked threats
- [T1132](https://intel.threadlinqs.com/technique/T1132) Data Encoding — Command and Control — observed in 2 of 4 tracked threats
- [T1204](https://intel.threadlinqs.com/technique/T1204) User Execution — Execution — observed in 2 of 4 tracked threats
- [T1218](https://intel.threadlinqs.com/technique/T1218) System Binary Proxy Execution — Stealth (formerly Defense Evasion) — observed in 2 of 4 tracked threats

## Tracked threats

- [SmartApeSG ClickFix Campaign Delivering Two-Stage RAT Infection via Fake CAPTCHA Social Engineering on Windows Hosts](https://intel.threadlinqs.com/threat/TL-2026-2101) — HIGH
- [Multi-Stage NetSupport RAT Loader Using Layered Obfuscation (Decimal Arrays, AES, GZIP)](https://intel.threadlinqs.com/threat/TL-2026-1487) — MEDIUM
- [SmartApeSG ClickFix Campaign Delivers NetSupport Manager RAT via Two-Stage Loader (Unidentified Initial RAT, Encoded TCP/443 C2)](https://intel.threadlinqs.com/threat/TL-2026-0647) — HIGH
- [SmartApeSG ClickFix Campaign Delivers Remcos RAT via Fake CAPTCHA Pages](https://intel.threadlinqs.com/threat/TL-2026-0225) — HIGH

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/SmartApeSG
