Last seven days
- First activity
- Aug 1, 2026
- Last activity
- Aug 7, 2026
- Feed role
- C2 / Distribution
- Host form
- 9 IP / 4 hostnames
SectopRAT is a Windows remote access trojan active since at least 2019 that combines hands-on remote control with broad information-stealing functionality.
Profile source: Mallory opens in a new tabSectopRAT
SectopRAT is a Windows remote access trojan active since at least 2019 that combines hands-on remote control with broad information-stealing functionality. It is used to harvest browser credentials, cookies, autofill data, payment card details, messaging application data, FTP and VPN-related data, personal files, and other sensitive user information. Reported variants and campaigns also show browser-session interception behavior, including relaying visited URLs and submitted form fields to attacker infrastructure, enabling theft of authenticated web activity and plaintext credentials. Some reporting also associates the malware family with hidden virtual network computing functionality and real-time operator interaction on compromised hosts.
SectopRAT has been delivered through multiple intrusion chains, including malvertising, ClickFix-style social engineering, drive-by delivery via loaders, and abuse of trusted platforms and signed binaries. A prominent 2026 campaign used sponsored search results for a fake Claude desktop application, redirected victims through a malicious page hosted on a legitimate service, and deployed SectopRAT through DLL sideloading with signed executables. Other observed delivery ecosystems include Dolphin Loader, DarkGate-related chains, and HiJack Loader-associated activity. The malware has also appeared in broader ClickFix operations, where victims are tricked into executing attacker-supplied commands.
The malware and its loaders employ substantial defense-evasion tradecraft. Observed campaigns used packing, virtual-machine and GPU checks, shader-based payload decryption, signed-binary proxy execution, scheduled-task persistence, Microsoft Defender exclusions, and cleanup routines. Some SectopRAT operations retrieve command-and-control information through blockchain-based EtherHiding techniques, while others communicate directly with hard-coded IP addresses, bypassing DNS-based monitoring and blocking controls. Direct-to-IP command-and-control has been documented in campaigns targeting educational institutions.
SectopRAT is associated with credential theft, data exfiltration, persistence, and post-compromise remote access. It has been observed in campaigns affecting multiple organizations and sectors, including education, and is frequently positioned as a final payload within commodity malware delivery ecosystems that enable sustained operator access after initial infection.
C2 tracking
Derp observations, rolling seven-day window
Samples
5ce830436e2cb3a0f6e3cd218cacbb30ba38f5da9031170f5b5b01bcf38c382d cb336a6e3fc0e9aa62b5768bffc207c09b372546636a5c58057a1b6d0708df06 06f6a0dc417bf0c8d1fa54754f53d37d190a3b9bf66658e00a630ae0bb56dfab 2ab248b392653566fe4fb34e2ced50acd8e91941010f38e2a85c792968261f20 b3708f27ddaebb5f2f256416e5082de39dd48d2a9b2bf0e9076794c3c4ca8506 0794db73759ee87450b45bde86b7ecc226e97f4dfd7cce528c975f4a4f695fcb 3b2981e34476ea28d555b8e8e18e625ad6e6ab5d60aff812f5cf2ab1ca8eb3fa 4987193675d0a5249df2ade38ba061a49e199bee1eb019faf11b6f4195b46ee0 4c245ae9f80db604f285eeb27f05964cc2f1dbd35f2cf2e60736fed39ffa5f7b e868b7b909257aa6869e05cc14d4de54b1dbece980bcffb1fd20bba3708e5007 Reported operators
The final payload was identified as SectopRAT, a remote access trojan with credential and data-theft behavior.
These malware families are frequently observed as initial infection vectors that deliver a wide range of secondary payloads, including SectopRAT, WarmCookie, HijackLoader, NetSupport RAT...
The PowerShell dropper ( bruce.php ) unpacks through five stages -- XOR decryption, reflective .NET assembly loading, AES-256-CBC decryption, Donut shellcode injection via raw NTDLL syscalls -- before deploying the final SectopRAT info-stealer targeting browser credentials, email clients, and cryptocurrency wallets.
…XENORAT, SECTOPRAT, MARSSTEALER…
Operators connect via C2, run system reconnaissance, and can drop SectopRAT as a secondary payload.
Operators connect via C2, run system reconnaissance, and can drop SectopRAT as a secondary payload.
MITRE ATT&CK
Reporting
Microsoft reported that social-engineering lures are increasingly being used to trick users into launching malware themselves, with the ClickFix technique emerging as a major delivery method across phishing, malvertising, and compromised websites. In ClickFix attacks, victims are shown fake CAPTCHA, verification, or repair prompts that copy malicious commands to the clipboard and persuade them to run them, often leading to fileless execution through LOLBins, obfuscated PowerShell, and follow-on payloads such as Lumma Stealer, DarkGate, Latrodectus, ScreenConnect, and AMOS. Microsoft said the technique has hit thousands of enterprise and consumer devices daily and is now supported by a growing underground market of ClickFix builder kits sold on criminal forums. Fresh activity shows the tactic continuing to evolve. A SmartApeSG campaign observed on compromised web traffic redirected victims to a fake human-verification flow that fetched an HTA downloader from deltaode[.]com, retrieved a ZIP archive, and abused DLL side-loading to launch an unidentified RAT that later communicated with 89.124.79[.]98 over TCP 443. Separately, Microsoft linked the CaptiveCrunch campaign to Storm-2945, a sub-cluster of Russia-linked Midnight Blizzard, which has manipulated DNS and HTTP traffic on hospitality and other captive-portal networks to redirect travelers to phishing pages and fake browser or OS updates delivering CornFlake and ChocoShell for credential theft and espionage, including theft of browser credentials, Microsoft 365 tokens, and Wi-Fi credentials.
A malvertising campaign dubbed FakeAgent abused searches for the Claude Desktop app to deliver the SectopRAT information-stealing trojan to Windows users at at least 29 organizations. Victims who clicked sponsored Bing results were sent to a spoofed public artifact hosted on Anthropic's claude.ai domain instead of the legitimate download page, then redirected to attacker-controlled infrastructure that served a fake ClaudeDesktop.exe installer. Huntress said the activity ran from July 21 to 22 and should be treated as a full remote-access and credential-theft compromise, not a nuisance adware incident. The malware chain used DLL sideloading through a tampered libcef.dll, signed-binary proxy execution, VMProtect packing, GPU-based anti-analysis, and DirectX shader-based payload decryption to evade detection. Researchers said SectopRAT established persistence with sslconf.exe, tempdir.dll, and appcfg.dat under AppData, and retrieved command data via blockchain infrastructure tied to contract 0xc1907d7be91f95903ad66d775c397302e7dd9228; Huntress also identified 2.24.131[.]246 as a live command-and-control address. The RAT is capable of stealing browser credentials, cookies, autofill and payment data, Chromium keys, FTP credentials, Discord and messaging data, files, and passwords, and the infrastructure was linked to earlier malicious activity dating to May 2025, including domains associated with campaigns tied to StealC infrastructure seized during Operation Endgame.
Security researchers reported that ClickFix has expanded into an industrialized malware-delivery ecosystem that relies on social engineering rather than software exploits. Attackers use fake CAPTCHA checks, browser updates, meeting errors, and verification prompts to trick users into manually running attacker-supplied commands through trusted tools such as PowerShell, mshta, curl, Windows Run, or macOS Terminal. ReversingLabs said the ecosystem now supports a wide range of payloads, including Lumma Stealer, DarkGate, XWorm, AsyncRAT, NetSupport, and SectopRAT, while related variants such as CrashFix, FileFix, PromptFix, and ConsentFix continue to emerge. The activity is being amplified through large-scale web compromise campaigns. Reports linked the DriveSurge actor to active ClickFix and FakeUpdates operations abusing thousands of compromised websites to distribute malware, while a separate SlowMist investigation documented a Google Sites-hosted phishing campaign targeting Web3 users on macOS with a fake community application flow that pushed victims to download a .scpt file or run a Base64-encoded Terminal command. That infection chain delivered a Mach-O stealer resembling AMOS (Atomic macOS Stealer), which harvested browser credentials, cookies, Keychain data, Apple Notes, Telegram Desktop data, and cryptocurrency wallet files before archiving data to /tmp/lksopo.zip and exfiltrating it to 86.54.25.213. Researchers said structural YARA detection of lure pages is currently one of the most effective ways to identify these campaigns, which often evade traditional AV and EDR controls because they depend on legitimate tools and user-approved execution.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.