Valid Points · July 2026
Claude Desktop Malvertising, SmartApeSG Fake Updates, and Validin at Black Hat 2026
How PacketWatch traced the SmartApeSG/ZPHP fake-update campaign to 32 unreported indicators, ASN filtering in Advanced Search, and where to find us at Black Hat.
Welcome back to Validin’s monthly newsletter and thank you for inviting us into your inbox. This month we're highlighting our partnership with PacketWatch and demonstrating how they use Validin to trace the SmartApeSG/ZPHP fake-update campaign. On the product side, we've upgraded our advanced search capabilities with ASN filtering. Next week, we're heading to Black Hat. Come find us at Booth #6200 to get something a little more valuable than merch...
The Validin Team
FEATURED RESEARCH
💼 Case Study: Packetwatch product and research integration with Validin
Building on a malicious session identified in PacketWatch WireSight, PacketWatch traced the SmartApeSG/ZPHP fake-update campaign using Validin's threat-feed enrichment, JavaScript redirects, metadata pivots, body hashes, and favicon reuse. They identified 32 previously unreported domains and IP addresses, then brought the full indicator set back into WireSight to uncover related client traffic and enable future detections.
BY THE NUMBERS
Top-viewed threat actor profiles and how their ranking changed from last month. If you're logged into Validin, you can view the full profiles:
- ClickFix (+1)
- Lazarus Group (+1)
- Kimsuky (-2)
- Transparent Tribe (new)
- Fake Software Downloads (-1)
PLATFORM UPDATES
💬 Filtering by ASN in Advanced Search
This July, we enabled a much requested advanced search feature: network filters. Users can now input CIDRs into any compatible IP field and globally filter results by ASN. With this we've enabled pivots that were previously hard to achieve.

IN CASE YOU MISSED IT
👋 See you at Black Hat
The Validin team is heading to Black Hat next week! Drop by booth #6200 to get a poker chip worth more than what you are likely to win in the casino!
SPOT VALIDIN IN...
🎭 Inside FakeAgent: How a Claude Desktop Malvertising Campaign Hit 29 Organizations with SectopRAT
Huntress documented FakeAgent, a malvertising campaign that abused a public Claude Artifact and fake Claude Desktop installer to deliver SectopRAT across at least 29 organizations. The investigation traced DLL sideloading, GPU-based anti-analysis and payload decryption, and blockchain-hosted command-and-control infrastructure. Read the full analysis here.
ONE LAST NOTE...
📝 Validin Terms Update
To better serve and support users on the Community and Enterprise editions of Validin, we have updated our Terms of Use to include company updates (we are now Validin, Inc.) and addressing some mutual elements for customers and users. Please reference the updated Terms of Use here.
Get in touch
Contact us
Validin is the first tab I open every morning.
