Malware

SectopRAT

Also known as: 1xxbot · ArechClient

SectopRAT, aka ArechClient2, is a .NET RAT with numerous capabilities including multiple stealth functions. Arechclient2 can profile victim systems, steal information such as browser and crypto-wallet data, and launch a hidden secondary desktop to control browser sessions. Additionally, it has several anti-VM and anti-emulator capabilities.

Indicators of Compromise 29

MITRE ATT&CK TTPs 17

Source Articles

Almost Half of Malware Samples Communicate Direct to IP
A significant portion of malware samples bypass DNS by communicating directly to IP addresses, evading DNS-based security controls. Analysis of 4 million dynamic reports shows 45.32% of malware with command-and-control (C2) activity used direct-to-IP (D2IP) connections, accounting for 23.17% of all C2 attempts. Threats identified include Phorpiex ransomware droppers, a data exfiltration campaign using obfuscated \GET requests, SectopRAT deployments targeting educational institutions, and IoT botnets like Mozi and a new Mirai variant named Boatnet. These threats leverage hard-coded IP addresses and custom HTTP methods to avoid detection and maintain persistence.
unit42 ·4w ago
Fake Claude app promoted by Bing ads pushes SectopRAT malware
A malvertising campaign leveraging Bing ads promotes a fake Claude desktop application to distribute the SectopRAT remote access trojan. The malicious installer, ClaudeDesktop.exe, sideloads a malicious DLL to deploy the malware, which establishes persistence via a scheduled task under the name DockerDesktop.exe. SectopRAT, also known as ArechClient2, steals credentials, files, and sensitive data from browsers and messaging apps, using Ethereum transactions to retrieve C2 addresses. The campaign, dubbed FakeAgent, has compromised at least 29 organizations and uses anti-analysis techniques to evade detection.
bleeping-computer ·1mo ago
ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories
Recent cyber threats include malicious npm and PyPI packages delivering infostealers, counterfeit VS Code extensions exfiltrating machine data, and Android spyware disguised as legitimate safety apps. Iranian-affiliated actors are targeting PLC systems in critical infrastructure, while attackers leverage AI models for prompt injection and malware development. Campaigns also involve malvertising distributing SectopRAT and MarkiRAT, DNS tunneling by TrickBot for C2 communication, and exploitation of trust in legitimate platforms to deliver malware.
hacker-news ·1mo ago