SectopRAT is a Windows remote access trojan active since at least 2019 and also referred to as ArechClient or ArechClient2 in some reporting. It is used as a credential- and data-theft RAT that provides attackers with persistent remote access while harvesting browser credentials, cookies, autofill data, payment card details, personal information, messaging-client data, FTP data, Steam and VPN-related data, and files. Reported tradecraft also includes Hidden Virtual Network Computing functionality and in-browser proxying that can mirror victim browsing activity and capture submitted form data, including credentials, in real time.
SectopRAT has been observed delivered as a follow-on payload by malware loaders including FakeBat, through malvertising campaigns such as fake software installers and fake Claude desktop lures, through ClickFix-style social-engineering chains, and in trojanized installer scenarios abusing legitimate signed binaries for DLL sideloading. Campaigns have used trusted platforms and sponsored search results to increase credibility, and some intrusions targeted educational institutions.
The malware employs substantial defense-evasion measures. Reported protections include VMProtect packing, virtual-machine and graphics-hardware checks, shader-based payload decryption, and other anti-analysis logic. SectopRAT operators have also used blockchain-based EtherHiding to retrieve command-and-control information and, in some cases, direct-to-IP communications that bypass DNS-based visibility. Additional observed execution tradecraft includes process injection and signed-binary proxy execution via DLL sideloading.
SectopRAT is associated with hands-on-keyboard post-compromise activity typical of RAT operations, including persistence, interactive control, and data exfiltration. In broader delivery ecosystems such as ClickFix, it has been grouped with malware used to enable lateral movement and sustained access. The malware has been used in financially motivated intrusion activity and commodity malware distribution campaigns rather than being tied in the available information to a single confidently identified threat actor.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The final payload was identified as SectopRAT, a remote access trojan with credential and data-theft behavior.
These malware families are frequently observed as initial infection vectors that deliver a wide range of secondary payloads, including SectopRAT, WarmCookie, HijackLoader, NetSupport RAT...
The PowerShell dropper ( bruce.php ) unpacks through five stages -- XOR decryption, reflective .NET assembly loading, AES-256-CBC decryption, Donut shellcode injection via raw NTDLL syscalls -- before deploying the final SectopRAT info-stealer targeting browser credentials, email clients, and cryptocurrency wallets.
Operators connect via C2, run system reconnaissance, and can drop SectopRAT as a secondary payload.
Operators connect via C2, run system reconnaissance, and can drop SectopRAT as a secondary payload.
30 distinct techniques documented for this family, organized by ATT&CK tactic.
Over the past few years, cybercriminals have increasingly used the drive-by download technique to distribute malware via user web browsing.
Traditional software supply chain compromise, the manipulation of source code or update/distribution mechanisms (T1195.002), remains rare.
In addition to likely cyber espionage incidents, we observed suspected financially motivated compromises with broader distribution. In two separate incidents threat actors compromised underlying software used in consumer-facing websites
The infection chain starts with a simple Bing search for “CLAUDE DESKTOP APP.” Sponsored results fill the top of the page with lookalike download sites.
Persistence on the system is achieved through another executable named DockerDesktop.exe, which installs a scheduled task.
An identical copy called DockerDesktop.exe is later written as a scheduled task so the infection can restart after reboot.
PowerShell behavior: One or more execution delays via sleep command Connect to C2 to signal “start” Download payload from URL ending in .jpg Connect to C2 to signal “install” Load payload assembly using PowerShell
It downloads Redline Stealer binary disguised as a jpg file ... and SectopRAT/ArechClient ... Additional details on the PowerShell script can be seen in the annotated image below.
Persistence on the system is achieved through another executable named DockerDesktop.exe, which installs a scheduled task.
The domain names suggest an array of brands are impersonated in these attacks, including Microsoft, Zoom, Adobe, Steam, OpenAI
The SectopRAT payload ... is written to AppData\Local\Temp\ and injected into MsBuild.exe.
That stage checks graphics hardware and video memory to avoid sandboxes, then decrypts a hidden payload with a graphics shader instead of ordinary CPU code.
When launched, the package executes with elevated privileges then executes an embedded PowerShell script then drops and executes a legitimate copy of the Steam installer as a decoy.
The first, /churl (shown in Figure 4), relays every URL the victim visits, including: Authenticated session pages Single sign-on (SSO) redirects Learning management system content
Among traffic flagged by ZT-IP, we observed the following suspicious HTTP GET request toward the destination IP address at 178.16.54[.]109... The observed request exhibits multiple variations, including sequential numeric GET paths (e.g., /1 through /6) and specific file downloads. | Malware samples often bypass DNS entirely, communicating directly to IP addresses instead. Our analysis of 4 million dynamic analysis reports indicates that almost half (45.32%) of malware samples with any command-and-control (C2) activity made at least one direct-to-IP (D2IP) address connection.
Both actors leverage SectopRAT's in-browser proxy capability to silently mirror all victim browser traffic to attacker-controlled servers in real time.
The research highlights malware that bypasses traditional DNS-based detection by communicating directly with hardcoded IP addresses instead of resolving domain names.
FakeBat primarily aims to download and execute the next-stage payload, such as IcedID, Lumma, Redline, SmokeLoader, SectopRAT and Ursnif.
246 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
63 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remote access trojan used as the final payload in the FakeAgent malvertising campaign. It steals passwords, credit card data, personal information, and files, and uses VMProtect, virtual machine detection, and Ethereum blockchain-based command-and-control for evasion and attacker communications.
A remote access trojan highlighted for communicating directly with hard-coded IP addresses instead of using DNS, helping it evade DNS-based detection and blocking.
A remote access trojan used here against educational institutions, featuring an in-browser proxy that mirrors victim browser traffic and exfiltrates submitted form data including usernames and plaintext passwords over direct-to-IP connections.
Trojan mentioned only as part of background on earlier malvertising campaigns involving fake AI desktop lures.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.