Skip to content

SectopRAT

SectopRAT is a Windows remote access trojan active since at least 2019 that combines hands-on remote control with broad information-stealing functionality.

Profile source: Mallory opens in a new tab

SectopRAT

Family profile

SectopRAT is a Windows remote access trojan active since at least 2019 that combines hands-on remote control with broad information-stealing functionality. It is used to harvest browser credentials, cookies, autofill data, payment card details, messaging application data, FTP and VPN-related data, personal files, and other sensitive user information. Reported variants and campaigns also show browser-session interception behavior, including relaying visited URLs and submitted form fields to attacker infrastructure, enabling theft of authenticated web activity and plaintext credentials. Some reporting also associates the malware family with hidden virtual network computing functionality and real-time operator interaction on compromised hosts.

SectopRAT has been delivered through multiple intrusion chains, including malvertising, ClickFix-style social engineering, drive-by delivery via loaders, and abuse of trusted platforms and signed binaries. A prominent 2026 campaign used sponsored search results for a fake Claude desktop application, redirected victims through a malicious page hosted on a legitimate service, and deployed SectopRAT through DLL sideloading with signed executables. Other observed delivery ecosystems include Dolphin Loader, DarkGate-related chains, and HiJack Loader-associated activity. The malware has also appeared in broader ClickFix operations, where victims are tricked into executing attacker-supplied commands.

The malware and its loaders employ substantial defense-evasion tradecraft. Observed campaigns used packing, virtual-machine and GPU checks, shader-based payload decryption, signed-binary proxy execution, scheduled-task persistence, Microsoft Defender exclusions, and cleanup routines. Some SectopRAT operations retrieve command-and-control information through blockchain-based EtherHiding techniques, while others communicate directly with hard-coded IP addresses, bypassing DNS-based monitoring and blocking controls. Direct-to-IP command-and-control has been documented in campaigns targeting educational institutions.

SectopRAT is associated with credential theft, data exfiltration, persistence, and post-compromise remote access. It has been observed in campaigns affecting multiple organizations and sectors, including education, and is frequently positioned as a final payload within commodity malware delivery ecosystems that enable sustained operator access after initial infection.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Dll Sideloading
  • Exfiltration
  • Persistence
  • Post Exploitation
  • Session Hijacking

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 1, 2026
Last activity
Aug 7, 2026
Feed role
C2 / Distribution
Host form
9 IP / 4 hostnames

Leading locations

  • US7
  • NL2
  • DE1
  • FR1
  • HK1
  • SC1

Leading providers

  • Cloudflare, Inc.4
  • ChangLian Network Technology Co., Limited1
  • Cox Communications Inc.1
  • Hetzner Online GmbH1
  • LeaseWeb Netherlands B.V.1
  • Microsoft Corporation1

Infrastructure traits

  • Hosting 11
  • Anycast 4
  • Proxy 1

Samples

Recent associated samples

Reported operators

Threat actors

6 named in public reporting
FakeAgent

The final payload was identified as SectopRAT, a remote access trojan with credential and data-theft behavior.

TAG-150

These malware families are frequently observed as initial infection vectors that deliver a wide range of secondary payloads, including SectopRAT, WarmCookie, HijackLoader, NetSupport RAT...

Gamaredon Group

The PowerShell dropper ( bruce.php ) unpacks through five stages -- XOR decryption, reflective .NET assembly loading, AES-256-CBC decryption, Donut shellcode injection via raw NTDLL syscalls -- before deploying the final SectopRAT info-stealer targeting browser credentials, email clients, and cryptocurrency wallets.

UAC-0050

…XENORAT, SECTOPRAT, MARSSTEALER…

SmartApeSG

Operators connect via C2, run system reconnaissance, and can drop SectopRAT as a secondary payload.

GrayCharlie

Operators connect via C2, run system reconnaissance, and can drop SectopRAT as a secondary payload.

MITRE ATT&CK

SectopRAT in ATT&CK

71 distinct techniques

Techniques

71 techniques
T1071 Application Layer Protocol T1095 Non-Application Layer Protocol T1090 Proxy T1539 Steal Web Session Cookie T1568 Dynamic Resolution T1574.001 DLL T1555 Credentials from Password Stores T1583 Acquire Infrastructure T1053 Scheduled Task/Job T1566.002 Spearphishing Link T1497 Virtualization/Sandbox Evasion T1005 Data from Local System T1195 Supply Chain Compromise T1195.001 Compromise Software Dependencies and Development Tools T1189 Drive-by Compromise T1566.003 Spearphishing via Service T1219 Remote Access Tools T1140 Deobfuscate/Decode Files or Information T1059 Command and Scripting Interpreter T1566 Phishing T1053.005 Scheduled Task T1649 Steal or Forge Authentication Certificates T1562.001 Disable or Modify Tools T1041 Exfiltration Over C2 Channel T1027 Obfuscated Files or Information T1036 Masquerading T1608.006 SEO Poisoning T1204 User Execution T1656 Impersonation T1012 Query Registry T1120 Peripheral Device Discovery T1102 Web Service T1082 System Information Discovery T1547.001 Registry Run Keys / Startup Folder T1059.010 AutoHotKey & AutoIT T1112 Modify Registry T1518.001 Security Software Discovery T1614.001 System Language Discovery T1055 Process Injection T1055.012 Process Hollowing T1033 System Owner/User Discovery T1059.001 PowerShell T1497.001 System Checks T1016 System Network Configuration Discovery T1105 Ingress Tool Transfer T1560 Archive Collected Data T1070.004 File Deletion T1185 Browser Session Hijacking T1056 Input Capture T1115 Clipboard Data T1204.002 Malicious File T1571 Non-Standard Port T1059.006 Python T1036.005 Match Legitimate Resource Name or Location T1547 Boot or Logon Autostart Execution T1218 System Binary Proxy Execution T1583.001 Domains T1106 Native API T1071.001 Web Protocols T1584.004 Server T1518 Software Discovery T1555.003 Credentials from Web Browsers T1114.001 Local Email Collection T1027.002 Software Packing T1620 Reflective Code Loading T1090.002 External Proxy T1566.001 Spearphishing Attachment T1553.002 Code Signing T1059.007 JavaScript T1560.001 Archive via Utility T1505.003 Web Shell

Reporting

Research mentioning SectopRAT

Jul 31
Malware News

CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft - Malware News - Malware Analysis, News and Indicators

Microsoft reported that social-engineering lures are increasingly being used to trick users into launching malware themselves, with the ClickFix technique emerging as a major delivery method across phishing, malvertising, and compromised websites. In ClickFix attacks, victims are shown fake CAPTCHA, verification, or repair prompts that copy malicious commands to the clipboard and persuade them to run them, often leading to fileless execution through LOLBins, obfuscated PowerShell, and follow-on payloads such as Lumma Stealer, DarkGate, Latrodectus, ScreenConnect, and AMOS. Microsoft said the technique has hit thousands of enterprise and consumer devices daily and is now supported by a growing underground market of ClickFix builder kits sold on criminal forums. Fresh activity shows the tactic continuing to evolve. A SmartApeSG campaign observed on compromised web traffic redirected victims to a fake human-verification flow that fetched an HTA downloader from deltaode[.]com, retrieved a ZIP archive, and abused DLL side-loading to launch an unidentified RAT that later communicated with 89.124.79[.]98 over TCP 443. Separately, Microsoft linked the CaptiveCrunch campaign to Storm-2945, a sub-cluster of Russia-linked Midnight Blizzard, which has manipulated DNS and HTTP traffic on hospitality and other captive-portal networks to redirect travelers to phishing pages and fake browser or OS updates delivering CornFlake and ChocoShell for credential theft and espionage, including theft of browser credentials, Microsoft 365 tokens, and Wi-Fi credentials.

Jul 31
Malware Traffic Analysis

Malware-Traffic-Analysis.net - 2026-07-31: SmartApeSG ClickFix campaign pushes unidentified RAT

Jul 24
Cyber Security News

FakeAgent Campaign Uses Malicious Bing Ads and Claude.ai Artifacts to Infect Corporate Users

A malvertising campaign dubbed FakeAgent abused searches for the Claude Desktop app to deliver the SectopRAT information-stealing trojan to Windows users at at least 29 organizations. Victims who clicked sponsored Bing results were sent to a spoofed public artifact hosted on Anthropic's claude.ai domain instead of the legitimate download page, then redirected to attacker-controlled infrastructure that served a fake ClaudeDesktop.exe installer. Huntress said the activity ran from July 21 to 22 and should be treated as a full remote-access and credential-theft compromise, not a nuisance adware incident. The malware chain used DLL sideloading through a tampered libcef.dll, signed-binary proxy execution, VMProtect packing, GPU-based anti-analysis, and DirectX shader-based payload decryption to evade detection. Researchers said SectopRAT established persistence with sslconf.exe, tempdir.dll, and appcfg.dat under AppData, and retrieved command data via blockchain infrastructure tied to contract 0xc1907d7be91f95903ad66d775c397302e7dd9228; Huntress also identified 2.24.131[.]246 as a live command-and-control address. The RAT is capable of stealing browser credentials, cookies, autofill and payment data, Chromium keys, FTP credentials, Discord and messaging data, files, and passwords, and the infrastructure was linked to earlier malicious activity dating to May 2025, including domains associated with campaigns tied to StealC infrastructure seized during Operation Endgame.

Jul 23
Trojan Killer News

Fake Claude Desktop Ads Dropped SectopRAT | Trojan Killer

Jul 23
Bleeping Computer

Fake Claude app promoted by Bing ads pushes SectopRAT malware

Jul 23
Help Net Security

How attackers hosted a fake Claude download page on the claude.ai domain - Help Net Security

Jul 23
Itsecurityguru

FakeAgent Campaign: Malicious Claude Artifact Used to Distribute SectopRAT to 29 Organisations - IT Security Guru

Jul 18
Cyberveille

ClickFix : une méthodologie d'attaque industrialisée invisible aux EDR et antivirus | CyberVeille

Security researchers reported that ClickFix has expanded into an industrialized malware-delivery ecosystem that relies on social engineering rather than software exploits. Attackers use fake CAPTCHA checks, browser updates, meeting errors, and verification prompts to trick users into manually running attacker-supplied commands through trusted tools such as PowerShell, mshta, curl, Windows Run, or macOS Terminal. ReversingLabs said the ecosystem now supports a wide range of payloads, including Lumma Stealer, DarkGate, XWorm, AsyncRAT, NetSupport, and SectopRAT, while related variants such as CrashFix, FileFix, PromptFix, and ConsentFix continue to emerge. The activity is being amplified through large-scale web compromise campaigns. Reports linked the DriveSurge actor to active ClickFix and FakeUpdates operations abusing thousands of compromised websites to distribute malware, while a separate SlowMist investigation documented a Google Sites-hosted phishing campaign targeting Web3 users on macOS with a fake community application flow that pushed victims to download a .scpt file or run a Base64-encoded Terminal command. That infection chain delivered a Mach-O stealer resembling AMOS (Atomic macOS Stealer), which harvested browser credentials, cookies, Keychain data, Apple Notes, Telegram Desktop data, and cryptocurrency wallet files before archiving data to /tmp/lksopo.zip and exfiltrating it to 86.54.25.213. Researchers said structural YARA detection of lure pages is currently one of the most effective ways to identify these campaigns, which often evade traditional AV and EDR controls because they depend on legitimate tools and user-approved execution.

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.