Skip to content

SectopRAT

SectopRAT, also known as ArechClient2, is a Windows .NET remote-access trojan active since at least 2019.

Profile source: Mallory opens in a new tab

SectopRAT

Family profile

SectopRAT, also known as ArechClient2, is a Windows .NET remote-access trojan active since at least 2019. It combines interactive remote-control functionality, including Hidden Virtual Network Computing capabilities, with theft of browser credentials, cookies, autofill records, payment-card data, FTP credentials, messaging-client data, VPN-related data, personal files, and other user information. Its collection of browser cookies and its ability to relay browser traffic and submitted form data can expose authenticated web sessions and plaintext credentials.

SectopRAT has been distributed as a later-stage payload by loaders including FakeBat and has appeared in malvertising and ClickFix operations. The FakeAgent campaign used sponsored search results and a counterfeit Claude desktop download page hosted through a legitimate platform to deliver the trojan to Windows users. The delivery chain abused signed applications for DLL sideloading, created scheduled-task persistence, and added Microsoft Defender exclusions.

Observed SectopRAT-related loaders and payloads employ VMProtect packing, virtual-machine and graphics-hardware checks, and shader-based payload decryption to impede analysis. SectopRAT has used EtherHiding to obtain command-and-control configuration from blockchain transaction data, allowing operators to change infrastructure without relying on conventional fixed domains. Campaigns using direct-to-IP communications have targeted educational institutions. Available reporting does not support a confident attribution of the FakeAgent operation to a specific known threat actor.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Dll Sideloading
  • Exfiltration
  • Persistence
  • Post Exploitation
  • Process Injection
  • Session Hijacking

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 22, 2026
Last activity
Aug 29, 2026
Feed role
C2 / Distribution
Host form
15 IP / 4 hostnames

Leading locations

  • NL6
  • US6
  • HK2
  • CH1
  • FI1
  • IT1
  • SG1

Leading providers

  • RootLayer Web Services LLC3
  • Cloudflare, Inc.2
  • BlueVPS OU1
  • ChangLian Network Technology Co., Limited1
  • Cox Communications Inc.1
  • DEDIK SERVICES LIMITED1

Infrastructure traits

  • Hosting 14
  • Anycast 2

Samples

Recent associated samples

Reported operators

Threat actors

6 named in public reporting
FakeAgent

The final payload was identified as SectopRAT, a remote access trojan with credential and data-theft behavior.

TAG-150

These malware families are frequently observed as initial infection vectors that deliver a wide range of secondary payloads, including SectopRAT, WarmCookie, HijackLoader, NetSupport RAT...

Gamaredon Group

The PowerShell dropper ( bruce.php ) unpacks through five stages -- XOR decryption, reflective .NET assembly loading, AES-256-CBC decryption, Donut shellcode injection via raw NTDLL syscalls -- before deploying the final SectopRAT info-stealer targeting browser credentials, email clients, and cryptocurrency wallets.

UAC-0050

…XENORAT, SECTOPRAT, MARSSTEALER…

SmartApeSG

Operators connect via C2, run system reconnaissance, and can drop SectopRAT as a secondary payload.

GrayCharlie

Operators connect via C2, run system reconnaissance, and can drop SectopRAT as a secondary payload.

MITRE ATT&CK

SectopRAT in ATT&CK

72 distinct techniques

Techniques

72 techniques
T1204.002 Malicious File T1566.002 Spearphishing Link T1036 Masquerading T1105 Ingress Tool Transfer T1219 Remote Access Tools T1568.003 DNS Calculation T1189 Drive-by Compromise T1583 Acquire Infrastructure T1055 Process Injection T1059.001 PowerShell T1568 Dynamic Resolution T1059 Command and Scripting Interpreter T1560 Archive Collected Data T1218 System Binary Proxy Execution T1204 User Execution T1649 Steal or Forge Authentication Certificates T1497 Virtualization/Sandbox Evasion T1005 Data from Local System T1071 Application Layer Protocol T1095 Non-Application Layer Protocol T1090 Proxy T1539 Steal Web Session Cookie T1574.001 DLL T1555 Credentials from Password Stores T1053 Scheduled Task/Job T1195 Supply Chain Compromise T1195.001 Compromise Software Dependencies and Development Tools T1566.003 Spearphishing via Service T1140 Deobfuscate/Decode Files or Information T1566 Phishing T1053.005 Scheduled Task T1562.001 Disable or Modify Tools T1041 Exfiltration Over C2 Channel T1027 Obfuscated Files or Information T1608.006 SEO Poisoning T1656 Impersonation T1012 Query Registry T1120 Peripheral Device Discovery T1102 Web Service T1082 System Information Discovery T1547.001 Registry Run Keys / Startup Folder T1059.010 AutoHotKey & AutoIT T1112 Modify Registry T1518.001 Security Software Discovery T1614.001 System Language Discovery T1055.012 Process Hollowing T1033 System Owner/User Discovery T1497.001 System Checks T1016 System Network Configuration Discovery T1070.004 File Deletion T1185 Browser Session Hijacking T1056 Input Capture T1115 Clipboard Data T1571 Non-Standard Port T1059.006 Python T1036.005 Match Legitimate Resource Name or Location T1547 Boot or Logon Autostart Execution T1583.001 Domains T1106 Native API T1071.001 Web Protocols T1584.004 Server T1518 Software Discovery T1555.003 Credentials from Web Browsers T1114.001 Local Email Collection T1027.002 Software Packing T1620 Reflective Code Loading T1090.002 External Proxy T1566.001 Spearphishing Attachment T1553.002 Code Signing T1059.007 JavaScript T1560.001 Archive via Utility T1505.003 Web Shell

Reporting

Research mentioning SectopRAT

Aug 26
Cyber Security News

Hackers Use Fake Claude Desktop App to Disable Defender and Install Remote Access Malware

A FakeAgent campaign is using malicious search advertisements and counterfeit Claude Desktop download pages to deliver the SectopRAT remote-access trojan to Windows users. The trojanized installer reportedly executes PowerShell to add Microsoft Defender exclusions, then uses DLL sideloading via a signed Java Chromium Embedded Framework helper and creates a disguised elevated scheduled task for persistence. Associated indicators include Claude-themed download infrastructure, lookalike application components, and IP address 153.75.84.173. SectopRAT retrieves encrypted connection information through EtherHiding, using Ethereum blockchain data instead of a conventional command-and-control server. Organizations should isolate potentially affected endpoints, identify and remove unauthorized Defender exclusions and scheduled tasks, revoke credentials and active sessions used on exposed hosts, review identity activity, and reimage systems where execution is confirmed.

Aug 26
Cryptika

Hackers Use Fake Claude Desktop App to Disable Defender and Install Remote Access Malware | Cryptika Cybersecurity

Aug 17
Huntress

MacSync Stealer: How a Google Search for Claude Led to a macOS Infostealer | Huntress

A malvertising campaign used sponsored Google search results for Anthropic's Claude to lure macOS users to a legitimate shared conversation page on claude.ai, where they were socially engineered into running a malicious terminal command. Huntress reported that the command fetched MacSync, a multi-stage macOS infostealer and remote access trojan that chains a zsh loader, in-memory AppleScript theft, a persistent Mach-O RAT, and a helper component designed to abuse Screen Recording permissions. The malware was built to steal a wide range of data from infected Macs, including browser data, Keychain secrets, saved passwords, Telegram sessions, SSH and cloud credentials, and cryptocurrency wallet recovery phrases. The operation also used repeated TCC permission prompts, fake "Apple Support" messaging, and trojanized cryptocurrency wallet applications to deepen access, maintain persistence, and expand theft beyond initial credential harvesting.

Aug 15
Github Web

GitHub - tjnel/certgraveyard_yara: Automated YARA rule generation from the Cert Central compromised certificate database. · GitHub

A public project called CertGraveyard has expanded efforts to document abused code-signing certificates used to sign malware, building a shared record of certificate abuse and helping defenders trigger revocations with certificate authorities. The project’s creator said the initiative grew out of years of reporting malicious certificates tied to malware such as SolarMarker, and has helped report more than 2,000 certificates, later growing to roughly 2,400 entries in the database. Supporting tooling includes certReport, which automates abuse reports from malware hashes using sources such as VirusTotal and MalwareBazaar, plus an API, downloadable datasets, feeds, hunting queries, and integrations with platforms including MalwareBazaar, UnpacMe, Malcat, MagicSword.io, and WDAC enforcement workflows. The database reflects a broader pattern in which threat actors repeatedly obtain or abuse valid Authenticode certificates to make malware appear trustworthy, reduce Windows warnings, and sustain delivery campaigns. Prior reporting cited SolarMarker cycling through impostor-issued certificates, FakeBat distributing signed MSI and MSIX installers, Netbounce using valid certificates and fake software branding, Dark Caracal signing Bandook variants with legitimate certificates, and Operation Red Signature abusing a stolen vendor certificate in a supply-chain intrusion. CertGraveyard’s operator said certificate authorities often act on external reports within hours, making revocation a practical disruption measure, though the project has also faced operational pressure including a major DDoS attack while handling heavy daily lookup and download volumes from defenders and malware-analysis integrations.

Jul 31
Malware News

CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft - Malware News - Malware Analysis, News and Indicators

Microsoft reported that social-engineering lures are increasingly being used to trick users into launching malware themselves, with the ClickFix technique emerging as a major delivery method across phishing, malvertising, and compromised websites. In ClickFix attacks, victims are shown fake CAPTCHA, verification, or repair prompts that copy malicious commands to the clipboard and persuade them to run them, often leading to fileless execution through LOLBins, obfuscated PowerShell, and follow-on payloads such as Lumma Stealer, DarkGate, Latrodectus, ScreenConnect, and AMOS. Microsoft said the technique has hit thousands of enterprise and consumer devices daily and is now supported by a growing underground market of ClickFix builder kits sold on criminal forums. Fresh activity shows the tactic continuing to evolve. A SmartApeSG campaign observed on compromised web traffic redirected victims to a fake human-verification flow that fetched an HTA downloader from deltaode[.]com, retrieved a ZIP archive, and abused DLL side-loading to launch an unidentified RAT that later communicated with 89.124.79[.]98 over TCP 443. Separately, Microsoft linked the CaptiveCrunch campaign to Storm-2945, a sub-cluster of Russia-linked Midnight Blizzard, which has manipulated DNS and HTTP traffic on hospitality and other captive-portal networks to redirect travelers to phishing pages and fake browser or OS updates delivering CornFlake and ChocoShell for credential theft and espionage, including theft of browser credentials, Microsoft 365 tokens, and Wi-Fi credentials.

Jul 31
Malware Traffic Analysis

Malware-Traffic-Analysis.net - 2026-07-31: SmartApeSG ClickFix campaign pushes unidentified RAT

Jul 28
Sekoia

Exposing FakeBat loader: distribution methods and adversary infrastructure

Jul 24
Cyber Security News

FakeAgent Campaign Uses Malicious Bing Ads and Claude.ai Artifacts to Infect Corporate Users

A malvertising campaign dubbed FakeAgent abused searches for the Claude Desktop app to deliver the SectopRAT information-stealing trojan to Windows users at at least 29 organizations. Victims who clicked sponsored Bing results were sent to a spoofed public artifact hosted on Anthropic's claude.ai domain instead of the legitimate download page, then redirected to attacker-controlled infrastructure that served a fake ClaudeDesktop.exe installer. Huntress said the activity ran from July 21 to 22 and should be treated as a full remote-access and credential-theft compromise, not a nuisance adware incident. The malware chain used DLL sideloading through a tampered libcef.dll, signed-binary proxy execution, VMProtect packing, GPU-based anti-analysis, and DirectX shader-based payload decryption to evade detection. Researchers said SectopRAT established persistence with sslconf.exe, tempdir.dll, and appcfg.dat under AppData, and retrieved command data via blockchain infrastructure tied to contract 0xc1907d7be91f95903ad66d775c397302e7dd9228; Huntress also identified 2.24.131[.]246 as a live command-and-control address. The RAT is capable of stealing browser credentials, cookies, autofill and payment data, Chromium keys, FTP credentials, Discord and messaging data, files, and passwords, and the infrastructure was linked to earlier malicious activity dating to May 2025, including domains associated with campaigns tied to StealC infrastructure seized during Operation Endgame.

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.