
SANS Stormcast Monday, March 16th, 2026: SmartApeSG and Remcos RAT; React Based Phishing; Google Chrome Patches; AdGaurd Vuln (#)
About this episode
Get every episode summarized
Each time SANS Internet Storm Center's Daily Network Security News Podcast publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
Hosts & guests
Transcript ready
78 searchable segments. Every word is indexed and playable.
Full transcript
SANS Internet Storm Center's Daily Network Security News Podcast — SANS Stormcast Monday, March 16th, 2026: SmartApeSG and Remcos RAT; React Based Phishing; Google Chrome Patches; AdGaurd Vuln (#). Machine-transcribed; use the interactive transcript above to jump the player to any line.
Hello and welcome to the Monday March 16th, 2020, 6th edition of the Sands, and then at StormCast, my name is Johannes, or a Recording Day from Jacksonville, Florida. And this episode is brought to you by the Sands.edu, Created Certificate Program in Purple Team Operations. And today we got a couple of interesting diaries to talk about. The first one is by Brad about a ClickFix campaign that is then pushing Remco's rat. Now this is all associated with smart ape SG threat actor that Brad has talked about before. In the past, they have deployed other rats like, for example, Net Support Manager. Overall, the attack is, well, what we have seen so many times where a victim is presented with a fake capture that tricks them into copy pasting a command into their window system
that will then download the malware. As usual, Brad is sharing also all the evidence, including packet captures and the like. So this is a great diary kind of to follow along Brad's analysis and learn also a little bit more about how to analyze these kind of compromises. And the second diary from this weekend comes from Jan and Jan is looking at an interesting fishing trick being played here. It all starts fairly straightforward. The victim receives a PDF. The PDF itself is harmless other than it contains a link to a Cloudflare worker. And that Cloudflare worker is used in order to display the fishing page with a lot of JavaScript. Now, the one trick here that the attacker is playing, the attacker is collecting of course credentials. And in the example that Jan shows, they're impersonating Dropbox. But they have to get the credential somehow to the attacker.
In the past, we have seen stuff used like Telegram, for example, is very popular, a bunch of different APIs. What they're using in this particular case is email JS. Email JS allows you to send email with JavaScript. Of course, JavaScript itself doesn't allow you to like speak SMTP or such. So instead they're connecting to the email JS web service that allows you to then send HTTP requests to the web service that will then result in the email being sent to the attacker. So an interesting twist on this. Of course, I think it's mixed a little bit easier than to actually find the attacker given that you can check what email JS account or so they're using. And that may be a little bit of vulnerability here in this particular scheme. But then again, as long as it lasts a day or two, that's probably all attackers need in order to call this particular fishing campaign successful. Well, and then we got a little bit of patch drama with Google Chrome on Thursday, Google
released a new version of Chrome stating that they patched two critical vulnerabilities in Google Chrome that were already exploited in the wild on Friday. They corrected to notice stating that this update actually only fixes one of these vulnerabilities. And the second is going to be updated in the next version of Google Chrome. So there is still an outstanding already exploited vulnerability that will hopefully be patched soon. Just now make sure that you keep Google Chrome patched. As I obviously say, at least once a day restart Google Chrome and once a week double check that you're running the latest version. And Microsoft published a blog post with details regarding a campaign they're currently observing that tricks users into downloading malicious VPN clients. It all starts with good old search on ancient optimization. So that's still a thing, sadly, if the user searches for VPN client, they're then being
directed to fake website that imitates the particular manufacturer. And then the download will actually capture the credentials as the user types them in. There are a number of different VPN clients being impersonated here by this particular malware, like Pulse Secure is like one, but also for net and a couple of other Cisco. I think also there's not a vulnerability really in any of these VPN systems, but just malicious software that the user is tricked into installing. It's ditchly signed using Chinese certificate unclear where that came from, but likely stolen from the rightful owner. And with all of the search engine optimization tricks and in many cases also paid malicious advertisements, of course, one defense is to run some kind of ad blocker.
Well, if you're running ad guard home, there's an update for you. It does fix an authentication issue that would allow an attacker to gain full access to ad guard home without valid credentials. I'm not even sure how severe this vulnerability or exploitable it is given that it does require a transition from HB2 clear text and to basically encrypt it or HB2 over TLS. And the browser's to be don't support HB2 clear text. So maybe difficult to exploit, but please keep your systems updated. And this time it's ad guards time. Well, and is it for today? So thanks for listening. Thanks for liking. Thanks for subscribing to this podcast and talk to you again tomorrow. Bye.
More episodes
More from SANS Internet Storm Center's Daily Network Security News Podcast

SANS Stormcast Friday, March 20th, 2026: Cowrie Strings; MSFT Intune Hardening;...
SANS Internet Storm Center's Daily Network Security News Podcast

SANS Stormcast Thursday, March 19th, 2026: Adminer Scans; Apple WebKit Patch; an...
SANS Internet Storm Center's Daily Network Security News Podcast

SANS Stormcast Wednesday, March 18th, 2026: IPv4 mapped IPv6; KVM Vulnerabilitie...
SANS Internet Storm Center's Daily Network Security News Podcast

SANS Stormcast Tuesday, March 17th, 2026: Proxy URLs; Local Network Address Rest...
SANS Internet Storm Center's Daily Network Security News Podcast