Last seven days
- First activity
- Aug 26, 2026
- Last activity
- Sep 2, 2026
- Feed role
- C2 / Distribution
- Host form
- 0 IP / 194 hostnames
ZPHP, also known as SmartApeSG, is a JavaScript-based downloader/loader campaign distributed through malicious or compromised websites.
Profile source: Mallory opens in a new tabZPHP
ZPHP, also known as SmartApeSG, is a JavaScript-based downloader/loader campaign distributed through malicious or compromised websites. It has been observed using fake browser update lures and, in later activity, fake CAPTCHA pages masquerading as Cloudflare Turnstile prompts combined with the ClickFix social engineering technique to trick users into manually executing malicious commands. The malware has been associated with malvertisement-driven delivery and has appeared repeatedly in MS-ISAC/CIS reporting, including campaigns affecting U.S. State, Local, Tribal, and Territorial (SLTT) government organizations.
Observed behavior includes delivery of additional malware and remote access tools such as NetSupport, Lumma Stealer, and Remcos RAT. In the 2026 SLTT campaign described by CIS, the infection chain involved malicious JavaScript injected into Node.js-based architectures, a fake CAPTCHA shown only to Windows users under certain timing conditions, execution of attacker-supplied commands via mshta.exe, retrieval of an HTA payload, and a hidden PowerShell stage that downloaded a ZIP archive from 193.42.38[.]42/limit into LOCALAPPDATA using a random six-digit filename with a .pdf extension. The archive contained more than 90 files, including malicious files autohealth.dat, ActionCenterHelper.dll, mega_altpllq.exe, and Multiple_Predict.dat. Mega_altpllq.exe triggered DLL sideloading of ActionCenterHelper.dll, which read autohealth.dat containing an encrypted Remcos payload disguised as PostgreSQL data, then decrypted and injected it into memory. Persistence for the Remcos payload was established via a scheduled task and a Windows Run registry key named Intel PLLQ Components.
High-confidence infrastructure and indicators mentioned in the reporting include middleware-render.js as a malicious JavaScript component, the next-stage HTA payload named rate, command-and-control infrastructure at 193.42.38[.]42, and an observed Remcos C2 at 192.144.56[.]80:443 over HTTPS using a self-signed certificate. ZPHP has been tracked as using malvertisement and compromised websites as infection vectors, with fake browser updates and fake CAPTCHA/ClickFix lures as key delivery mechanisms.
C2 tracking
Derp observations, rolling seven-day window
Samples
106216dfdf04a0f3cefbab160b03690efb47af8b218e58c880cc6af986f003b3 4269344f4080cd3e17c8c6f7ca693389f583d8e4491d4deb9319b58fecf4fc05 43ad1623db82daa04b7b279a7bed657142e79dc5aa91e93a9e98c4a3ad54eb1e f626eab7dfeed72454d5fc934afc8692885aaa7a7e12b9c4e2bf5bde0acb4e05 07d90cddfd8d7a698062bcb670e49414c174bcbf2b17a76157b1c1f04c8e265a 7d046cea94be91de7d0f53a6abfd3dc91d5550ed66202841fb5e509401178f50 80a6c9d27493bc1a3c106bbccd3877bc925e12582d1c5daef849524e1c1a9ef0 e8ef5ccb94ed536494cece84c43746be26173f0a897f1051c610f341d1159e45 1ebc4253f1d8be381f9acc30051afae2c0c515ba6d87dcb463165a9854173a80 4a12f552a5de87979ec37918f88da7ae13bc0cd7b7336e794bf66f4cde48df87 Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.