Last seven days
- First activity
- Aug 22, 2026
- Last activity
- Aug 29, 2026
- Feed role
- C2 / Distribution
- Host form
- 15 IP / 4 hostnames
SectopRAT, also known as ArechClient2, is a Windows .NET remote-access trojan active since at least 2019.
Profile source: Mallory opens in a new tabSectopRAT
SectopRAT, also known as ArechClient2, is a Windows .NET remote-access trojan active since at least 2019. It combines interactive remote-control functionality, including Hidden Virtual Network Computing capabilities, with theft of browser credentials, cookies, autofill records, payment-card data, FTP credentials, messaging-client data, VPN-related data, personal files, and other user information. Its collection of browser cookies and its ability to relay browser traffic and submitted form data can expose authenticated web sessions and plaintext credentials.
SectopRAT has been distributed as a later-stage payload by loaders including FakeBat and has appeared in malvertising and ClickFix operations. The FakeAgent campaign used sponsored search results and a counterfeit Claude desktop download page hosted through a legitimate platform to deliver the trojan to Windows users. The delivery chain abused signed applications for DLL sideloading, created scheduled-task persistence, and added Microsoft Defender exclusions.
Observed SectopRAT-related loaders and payloads employ VMProtect packing, virtual-machine and graphics-hardware checks, and shader-based payload decryption to impede analysis. SectopRAT has used EtherHiding to obtain command-and-control configuration from blockchain transaction data, allowing operators to change infrastructure without relying on conventional fixed domains. Campaigns using direct-to-IP communications have targeted educational institutions. Available reporting does not support a confident attribution of the FakeAgent operation to a specific known threat actor.
C2 tracking
Derp observations, rolling seven-day window
Samples
0f78a658b60f0879acccf0933d9ae8a5d2c188e9f16b8e6f7b01bd0cc9b5c4e1 27215e26b312b8b4f8fc51bdcea6741536dafc9267348284e2259e798aed0e4d 3755718db9d33f4aba2563de454d4530a308b41b1096c904102d08e2101f2020 4e5cebe1908e12e8a4ed1198fb01fb87871dbe54847855b11b3540dbc47bbe88 738eacc140159cd81dff41dd16c806eb7c0c8391c256f1738d75d0321f77ba2e 612150ea6972715f8b79d20aa153e2173bf06ca8d5d99e1d706332de1ae081c4 d05986e4e8a5d6818ae373894b7af0e78fddd99c57d1b3b76357dfcafefc0cbb 8c0d4045cfdb115176404d462df053a382832640ef94e699278ecd9e82b93327 5ce830436e2cb3a0f6e3cd218cacbb30ba38f5da9031170f5b5b01bcf38c382d 76a44a5802574fec485043b11b90e78adc863a360d260554da5960d5751ec2a7 Reported operators
The final payload was identified as SectopRAT, a remote access trojan with credential and data-theft behavior.
These malware families are frequently observed as initial infection vectors that deliver a wide range of secondary payloads, including SectopRAT, WarmCookie, HijackLoader, NetSupport RAT...
The PowerShell dropper ( bruce.php ) unpacks through five stages -- XOR decryption, reflective .NET assembly loading, AES-256-CBC decryption, Donut shellcode injection via raw NTDLL syscalls -- before deploying the final SectopRAT info-stealer targeting browser credentials, email clients, and cryptocurrency wallets.
…XENORAT, SECTOPRAT, MARSSTEALER…
Operators connect via C2, run system reconnaissance, and can drop SectopRAT as a secondary payload.
Operators connect via C2, run system reconnaissance, and can drop SectopRAT as a secondary payload.
MITRE ATT&CK
Reporting
A FakeAgent campaign is using malicious search advertisements and counterfeit Claude Desktop download pages to deliver the SectopRAT remote-access trojan to Windows users. The trojanized installer reportedly executes PowerShell to add Microsoft Defender exclusions, then uses DLL sideloading via a signed Java Chromium Embedded Framework helper and creates a disguised elevated scheduled task for persistence. Associated indicators include Claude-themed download infrastructure, lookalike application components, and IP address 153.75.84.173. SectopRAT retrieves encrypted connection information through EtherHiding, using Ethereum blockchain data instead of a conventional command-and-control server. Organizations should isolate potentially affected endpoints, identify and remove unauthorized Defender exclusions and scheduled tasks, revoke credentials and active sessions used on exposed hosts, review identity activity, and reimage systems where execution is confirmed.
A malvertising campaign used sponsored Google search results for Anthropic's Claude to lure macOS users to a legitimate shared conversation page on claude.ai, where they were socially engineered into running a malicious terminal command. Huntress reported that the command fetched MacSync, a multi-stage macOS infostealer and remote access trojan that chains a zsh loader, in-memory AppleScript theft, a persistent Mach-O RAT, and a helper component designed to abuse Screen Recording permissions. The malware was built to steal a wide range of data from infected Macs, including browser data, Keychain secrets, saved passwords, Telegram sessions, SSH and cloud credentials, and cryptocurrency wallet recovery phrases. The operation also used repeated TCC permission prompts, fake "Apple Support" messaging, and trojanized cryptocurrency wallet applications to deepen access, maintain persistence, and expand theft beyond initial credential harvesting.
A public project called CertGraveyard has expanded efforts to document abused code-signing certificates used to sign malware, building a shared record of certificate abuse and helping defenders trigger revocations with certificate authorities. The project’s creator said the initiative grew out of years of reporting malicious certificates tied to malware such as SolarMarker, and has helped report more than 2,000 certificates, later growing to roughly 2,400 entries in the database. Supporting tooling includes certReport, which automates abuse reports from malware hashes using sources such as VirusTotal and MalwareBazaar, plus an API, downloadable datasets, feeds, hunting queries, and integrations with platforms including MalwareBazaar, UnpacMe, Malcat, MagicSword.io, and WDAC enforcement workflows. The database reflects a broader pattern in which threat actors repeatedly obtain or abuse valid Authenticode certificates to make malware appear trustworthy, reduce Windows warnings, and sustain delivery campaigns. Prior reporting cited SolarMarker cycling through impostor-issued certificates, FakeBat distributing signed MSI and MSIX installers, Netbounce using valid certificates and fake software branding, Dark Caracal signing Bandook variants with legitimate certificates, and Operation Red Signature abusing a stolen vendor certificate in a supply-chain intrusion. CertGraveyard’s operator said certificate authorities often act on external reports within hours, making revocation a practical disruption measure, though the project has also faced operational pressure including a major DDoS attack while handling heavy daily lookup and download volumes from defenders and malware-analysis integrations.
Microsoft reported that social-engineering lures are increasingly being used to trick users into launching malware themselves, with the ClickFix technique emerging as a major delivery method across phishing, malvertising, and compromised websites. In ClickFix attacks, victims are shown fake CAPTCHA, verification, or repair prompts that copy malicious commands to the clipboard and persuade them to run them, often leading to fileless execution through LOLBins, obfuscated PowerShell, and follow-on payloads such as Lumma Stealer, DarkGate, Latrodectus, ScreenConnect, and AMOS. Microsoft said the technique has hit thousands of enterprise and consumer devices daily and is now supported by a growing underground market of ClickFix builder kits sold on criminal forums. Fresh activity shows the tactic continuing to evolve. A SmartApeSG campaign observed on compromised web traffic redirected victims to a fake human-verification flow that fetched an HTA downloader from deltaode[.]com, retrieved a ZIP archive, and abused DLL side-loading to launch an unidentified RAT that later communicated with 89.124.79[.]98 over TCP 443. Separately, Microsoft linked the CaptiveCrunch campaign to Storm-2945, a sub-cluster of Russia-linked Midnight Blizzard, which has manipulated DNS and HTTP traffic on hospitality and other captive-portal networks to redirect travelers to phishing pages and fake browser or OS updates delivering CornFlake and ChocoShell for credential theft and espionage, including theft of browser credentials, Microsoft 365 tokens, and Wi-Fi credentials.
A malvertising campaign dubbed FakeAgent abused searches for the Claude Desktop app to deliver the SectopRAT information-stealing trojan to Windows users at at least 29 organizations. Victims who clicked sponsored Bing results were sent to a spoofed public artifact hosted on Anthropic's claude.ai domain instead of the legitimate download page, then redirected to attacker-controlled infrastructure that served a fake ClaudeDesktop.exe installer. Huntress said the activity ran from July 21 to 22 and should be treated as a full remote-access and credential-theft compromise, not a nuisance adware incident. The malware chain used DLL sideloading through a tampered libcef.dll, signed-binary proxy execution, VMProtect packing, GPU-based anti-analysis, and DirectX shader-based payload decryption to evade detection. Researchers said SectopRAT established persistence with sslconf.exe, tempdir.dll, and appcfg.dat under AppData, and retrieved command data via blockchain infrastructure tied to contract 0xc1907d7be91f95903ad66d775c397302e7dd9228; Huntress also identified 2.24.131[.]246 as a live command-and-control address. The RAT is capable of stealing browser credentials, cookies, autofill and payment data, Chromium keys, FTP credentials, Discord and messaging data, files, and passwords, and the infrastructure was linked to earlier malicious activity dating to May 2025, including domains associated with campaigns tied to StealC infrastructure seized during Operation Endgame.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.