Last seven days
- First activity
- Sep 7, 2026
- Last activity
- Sep 11, 2026
- Feed role
- C2 / Distribution
- Host form
- 1 IP / 1319 hostnames
ZPHP, also known as SmartApeSG, is a JavaScript-based downloader/loader campaign distributed through malicious or compromised websites.
Profile source: Mallory opens in a new tabZPHP
ZPHP, also known as SmartApeSG, is a JavaScript-based downloader/loader campaign distributed through malicious or compromised websites. It has been observed using fake browser update lures and, in later activity, fake CAPTCHA pages masquerading as Cloudflare Turnstile prompts combined with the ClickFix social engineering technique to trick users into manually executing malicious commands. The malware has been associated with malvertisement-driven delivery and has appeared repeatedly in MS-ISAC/CIS reporting, including campaigns affecting U.S. State, Local, Tribal, and Territorial (SLTT) government organizations.
Observed behavior includes delivery of additional malware and remote access tools such as NetSupport, Lumma Stealer, and Remcos RAT. In the 2026 SLTT campaign described by CIS, the infection chain involved malicious JavaScript injected into Node.js-based architectures, a fake CAPTCHA shown only to Windows users under certain timing conditions, execution of attacker-supplied commands via mshta.exe, retrieval of an HTA payload, and a hidden PowerShell stage that downloaded a ZIP archive from 193.42.38[.]42/limit into LOCALAPPDATA using a random six-digit filename with a .pdf extension. The archive contained more than 90 files, including malicious files autohealth.dat, ActionCenterHelper.dll, mega_altpllq.exe, and Multiple_Predict.dat. Mega_altpllq.exe triggered DLL sideloading of ActionCenterHelper.dll, which read autohealth.dat containing an encrypted Remcos payload disguised as PostgreSQL data, then decrypted and injected it into memory. Persistence for the Remcos payload was established via a scheduled task and a Windows Run registry key named Intel PLLQ Components.
High-confidence infrastructure and indicators mentioned in the reporting include middleware-render.js as a malicious JavaScript component, the next-stage HTA payload named rate, command-and-control infrastructure at 193.42.38[.]42, and an observed Remcos C2 at 192.144.56[.]80:443 over HTTPS using a self-signed certificate. ZPHP has been tracked as using malvertisement and compromised websites as infection vectors, with fake browser updates and fake CAPTCHA/ClickFix lures as key delivery mechanisms.
C2 tracking
Derp observations, rolling seven-day window
Samples
15fc1bfa898680d715ba027f63d9a39cf6b54c3b4193f8375ee8a3b7f0aad7bc 9b2a814060d65c8937ae987da239f65561f22a2d77b581f1cfddf6098db6512b 9dab630e93697e9f2743b1a6963b6f2d895aa68af5165636c203473634bd7327 df3a6563b41e40104f7c15f8ad394f408c39aeb5b6e4fb2cbda029cae34df353 50cd143e56b5eaac19208d604a5ecea4cc0ee3ef6da798c5cc259234fc777db4 3a36b8ef3231b6c7c9d02baf12ca5387f21c1614d59122eb1548989a88f53e80 91791f511cb1a5700de7af8d96bd4118b61e1bc570f261f773e3782d8d4a9612 c9d6f566ca1e5b0975904d758991230d41308911e61aec482f400479871810c0 4b7ef869e5f64849dd0a38bb467dab3863432156e4a2e83acc8f3f54a224acd3 53cd7d659cdb8b184dc15fa1aa9a3d36ed165dae06685190c8e74976da40f51b Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.