SectopRAT, also known as ArechClient2, is a heavily obfuscated .NET-based remote-access trojan targeting Windows systems. Active since at least 2019, it combines interactive remote administration with extensive information theft. Operators can execute shell commands, capture the screen, manage files and processes, control remote-display functionality, restart compromised systems, deploy supplementary modules, and remove the malware on command.
SectopRAT steals saved browser credentials, cookies, autofill data, payment-card information, and files. It also targets data associated with email clients, gaming platforms, browser-based cryptocurrency wallets, and desktop cryptocurrency wallets. Collected information is packaged, encrypted, and sent to operator-controlled infrastructure. Some variants use AES-encrypted JSON command-and-control traffic and fallback mechanisms to recover alternate controller information.
Observed variants use layered encrypted payload staging, in-memory .NET execution, API hashing, control-flow obfuscation, randomized identifiers, and indirect calls to complicate analysis. Persistence and execution have included scheduled tasks and DLL sideloading through altered components of otherwise legitimate Windows applications. In one investigated intrusion, attackers locally or downstream tampered with digital-audio-workstation software; there was no evidence that the software vendor distributed a compromised product.
SectopRAT has been delivered through malicious advertising, SEO-poisoned and fraudulent download pages, ClickFix lures, fake software installers and updates, and loader families including FakeBat and GHOSTPULSE. The FakeAgent campaign used malicious AI-platform-hosted download lures and counterfeit Claude Desktop installers to distribute SectopRAT to Windows users. No single threat actor is conclusively attributable to all SectopRAT activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The final payload was identified as SectopRAT, a remote access trojan with credential and data-theft behavior.
These malware families are frequently observed as initial infection vectors that deliver a wide range of secondary payloads, including SectopRAT, WarmCookie, HijackLoader, NetSupport RAT...
The PowerShell dropper ( bruce.php ) unpacks through five stages -- XOR decryption, reflective .NET assembly loading, AES-256-CBC decryption, Donut shellcode injection via raw NTDLL syscalls -- before deploying the final SectopRAT info-stealer targeting browser credentials, email clients, and cryptocurrency wallets.
Operators connect via C2, run system reconnaissance, and can drop SectopRAT as a secondary payload.
Operators connect via C2, run system reconnaissance, and can drop SectopRAT as a secondary payload.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
“The first malicious component decrypted assembly code hidden in a database file” and “decrypted the final malware from a second database file.”
“The payload also replaced readable code names with random ones and complicated its execution flow.”
“That intermediate code resolved 187 Windows functions dynamically, concealing their names until execution.”
The encrypted SectopRAT payload was embedded in legitimate-looking database files.
“[It] prepared the .NET runtime, and started the 64-bit SectopRAT payload directly in memory.”
“An uninstall command could delete the running executable after a six-second delay.”
sdkcra.dll lit des données chiffrées dans Activation.Desktop.db ... Le payload SectopRAT est lu depuis pool.db ... déchiffré en mémoire.
Using these control commands, SectopRAT implements... Process and file management... [including] “ProcessManager”.
“It also searches for data stored by several applications and cryptocurrency wallets, including Thunderbird, Steam, Battle.net, Atomic Wallet, Exodus, Electrum, Daedalus Mainnet, MetaMask, Chain Browser Wallet, TronLink and Coinbase Wallet.” | “FortiGuard identified 29 commands that give the operator control over functions including ... file ... management.”
“The targets extended beyond browsers to Thunderbird, gaming applications, wallet extensions, and desktop cryptocurrency wallets.”
12 domaines de repli ... pour récupérer une IP C2 alternative via HTTP POST.
12 domaines de repli ... pour récupérer une IP C2 alternative via HTTP POST.
“If that failed, it contacted one of 12 backup endpoints to recover an alternative address through several decoding and decryption steps.”
“One command downloaded an additional browser extraction module.”
Il supporte 29 commandes C2 dont : Administration système distante, capture d’écran, shell distant; Gestion de processus et fichiers, redémarrage système.
290 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
78 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
SectopRAT is an existing remote-access trojan with extensive information-stealing functionality. This variant used a modified legitimate library, encrypted payloads concealed in database files, indirect execution through a Windows callback, dynamic API resolution, scheduled-task persistence, AES-encrypted C2, and fallback endpoints. It can steal browser passwords, cookies, autofill and payment-card data, Thunderbird data, gaming-application data, wallet-extension data, and desktop cryptocurrency-wallet data.
Remote-access trojan mentioned in a background example of a separate malicious Claude Artifact campaign.
RAT .NET x64 fortement obfusqué offrant 29 commandes C2 pour l’administration distante, l’exécution de shell, la capture d’écran, la gestion de processus et de fichiers, ainsi que le vol de données. Il cible notamment les identifiants, cookies, données de remplissage automatique et cartes bancaires des navigateurs, des portefeuilles de cryptomonnaies, et des identifiants d’applications email et de jeux. Il emploie le chargement latéral de DLL, du shellcode chiffré, une exécution en mémoire, des communications C2 AES et des domaines de repli.
Remote-access trojan delivered through a tampered legitimate audio-workstation application. It is decrypted and executed in memory, and provides remote device control, screen capture, process and file management, and sensitive-data collection.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.