Malware
SectopRAT
Also known as: 1xxbot · ArechClient
SectopRAT, aka ArechClient2, is a .NET RAT with numerous capabilities including multiple stealth functions. Arechclient2 can profile victim systems, steal information such as browser and crypto-wallet data, and launch a hidden secondary desktop to control browser sessions. Additionally, it has several anti-VM and anti-emulator capabilities.
Indicators of Compromise 29
Domain attacker-controlled domain Filename /churl Filename /fsave Filename /hiddenbin/ Filename ClaudeDesktop.exe Filename DockerDesktop.exe Filename libcef.dll Filename st.exe SHA-256 01a96eeafb72042b3f69afd21b4c9155dbfe7f97ab3dca392972ad531a075ac2 SHA-256 9639f7ebc6a6d69d7bf5b8bc869e7783a1406088f192868624ad8919e9bfd1d4 SHA-256 bf24277400cc453d530e4277d3bd24e96c5e409adef6970518bdc59205aa0241 SHA-256 cc43cdbe8eb9874f55fffbe23b560b673eb9f31fb9a953926bba29464fd2dd07 SHA-256 e310476c41ae4f6e3c4ed9bb88303ee6e5e1455bd7afe51cf48965ea7599e6e5 SHA-256 e3513922666c202c1ae5c06eea277ba10477868d6d89ce2819f4f8ff9070bc85 SHA-256 e5715e6611ef6bcb233f5d2098510dab3db408abbb728b00e1821bb255829373 IP 103[.]245[.]236[.]146 IP 154[.]92[.]19[.]71 IP 178[.]16[.]54[.]109 IP 178[.]16[.]54[.]31 IP 18[.]228[.]188[.]56 IP 194[.]76[.]227[.]94 IP 2[.]26[.]98[.]67 IP 206[.]189[.]229[.]43 IP 62[.]60[.]179[.]230 IP 87[.]120[.]107[.]33 IP 91[.]92[.]243[.]29 IP hardcoded IP Package @apexfdn/apex Package @copilot-mcp/apex
MITRE ATT&CK TTPs 17
T1001.003 T1014 T1027 T1048 T1053.005 T1059 T1059.001 T1071.001 T1071.003 T1071.004 T1082 T1090 T1114 T1120 T1497 T1539 T1555
Protocol or Service Impersonation
Command And Control
Rootkit
Defense Evasion
Obfuscated Files or Information
Defense Evasion
Exfiltration Over Alternative Protocol
Exfiltration
Scheduled Task
Execution
Command and Scripting Interpreter
Execution
PowerShell
Execution
Web Protocols
Command And Control
Mail Protocols
Command And Control
DNS
Command And Control
System Information Discovery
Discovery
Proxy
Command And Control
Email Collection
Collection
Peripheral Device Discovery
Discovery
Virtualization/Sandbox Evasion
Defense Evasion
Steal Web Session Cookie
Credential Access
Credentials from Password Stores
Credential Access
Source Articles
Almost Half of Malware Samples Communicate Direct to IP
A significant portion of malware samples bypass DNS by communicating directly to IP addresses, evading DNS-based security controls. Analysis of 4 million dynamic reports shows 45.32% of malware with command-and-control (C2) activity used direct-to-IP (D2IP) connections, accounting for 23.17% of all C2 attempts. Threats identified include Phorpiex ransomware droppers, a data exfiltration campaign using obfuscated \GET requests, SectopRAT deployments targeting educational institutions, and IoT botnets like Mozi and a new Mirai variant named Boatnet. These threats leverage hard-coded IP addresses and custom HTTP methods to avoid detection and maintain persistence.
unit42 ·4w ago
Fake Claude app promoted by Bing ads pushes SectopRAT malware
A malvertising campaign leveraging Bing ads promotes a fake Claude desktop application to distribute the SectopRAT remote access trojan. The malicious installer, ClaudeDesktop.exe, sideloads a malicious DLL to deploy the malware, which establishes persistence via a scheduled task under the name DockerDesktop.exe. SectopRAT, also known as ArechClient2, steals credentials, files, and sensitive data from browsers and messaging apps, using Ethereum transactions to retrieve C2 addresses. The campaign, dubbed FakeAgent, has compromised at least 29 organizations and uses anti-analysis techniques to evade detection.
bleeping-computer ·1mo ago
ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories
Recent cyber threats include malicious npm and PyPI packages delivering infostealers, counterfeit VS Code extensions exfiltrating machine data, and Android spyware disguised as legitimate safety apps. Iranian-affiliated actors are targeting PLC systems in critical infrastructure, while attackers leverage AI models for prompt injection and malware development. Campaigns also involve malvertising distributing SectopRAT and MarkiRAT, DNS tunneling by TrickBot for C2 communication, and exploitation of trust in legitimate platforms to deliver malware.
hacker-news ·1mo ago