Malware
SectopRAT
Also known as: 1xxbot · ArechClient
SectopRAT, aka ArechClient2, is a .NET RAT with numerous capabilities including multiple stealth functions. Arechclient2 can profile victim systems, steal information such as browser and crypto-wallet data, and launch a hidden secondary desktop to control browser sessions. Additionally, it has several anti-VM and anti-emulator capabilities.
Indicators of Compromise 7
MITRE ATT&CK TTPs 15
T1001.003 T1014 T1027 T1053.005 T1059.001 T1071.001 T1071.003 T1071.004 T1082 T1090 T1114 T1120 T1497 T1539 T1555
Protocol or Service Impersonation
Command And Control
Rootkit
Defense Evasion
Obfuscated Files or Information
Defense Evasion
Scheduled Task
Execution
PowerShell
Execution
Web Protocols
Command And Control
Mail Protocols
Command And Control
DNS
Command And Control
System Information Discovery
Discovery
Proxy
Command And Control
Email Collection
Collection
Peripheral Device Discovery
Discovery
Virtualization/Sandbox Evasion
Defense Evasion
Steal Web Session Cookie
Credential Access
Credentials from Password Stores
Credential Access
Source Articles
Fake Claude app promoted by Bing ads pushes SectopRAT malware
A malvertising campaign leveraging Bing ads promotes a fake Claude desktop application to distribute the SectopRAT remote access trojan. The malicious installer, ClaudeDesktop.exe, sideloads a malicious DLL to deploy the malware, which establishes persistence via a scheduled task under the name DockerDesktop.exe. SectopRAT, also known as ArechClient2, steals credentials, files, and sensitive data from browsers and messaging apps, using Ethereum transactions to retrieve C2 addresses. The campaign, dubbed FakeAgent, has compromised at least 29 organizations and uses anti-analysis techniques to evade detection.
bleeping-computer ·4d ago
ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories
Recent cyber threats include malicious npm and PyPI packages delivering infostealers, counterfeit VS Code extensions exfiltrating machine data, and Android spyware disguised as legitimate safety apps. Iranian-affiliated actors are targeting PLC systems in critical infrastructure, while attackers leverage AI models for prompt injection and malware development. Campaigns also involve malvertising distributing SectopRAT and MarkiRAT, DNS tunneling by TrickBot for C2 communication, and exploitation of trust in legitimate platforms to deliver malware.
hacker-news ·5d ago