Insikt Group has published its first report on GrayCharlie, a threat actor active since mid-2023 that overlaps with SmartApeSG. The group compromises WordPress sites by injecting malicious JavaScript that redirects visitors to fake browser update pages or ClickFix lures, ultimately delivering NetSupport RAT, with follow-on infections of Stealc and SectopRAT. Infrastructure is primarily hosted on MivoCloud and HZ Hosting Ltd. A notable cluster of at least 15 US law firm websites was compromised around November 2025, likely via a supply-chain attack involving a shared IT provider called SMB Team. Two distinct attack chains are detailed: one using fake browser update prompts and one using ClickFix fake CAPTCHA lures. The report includes extensive IoCs, YARA/Snort/Sigma detection rules, and mitigation guidance.