ArechClient2, also known as SectopRAT, is a heavily obfuscated .NET remote-access trojan and information stealer first reported in 2019. It targets Windows systems and supports remote command execution, host profiling, and theft of browser passwords, cookies, autofill data, cryptocurrency-wallet data, and credentials associated with FTP, VPN, and messaging or gaming applications. Its hidden secondary desktop capability can enable an operator to interact with a compromised system concurrently with its user. The malware incorporates anti-analysis and defense-evasion functionality, including anti-virtual-machine and anti-emulator checks, and has been loaded directly into memory by intermediate loaders that bypass AMSI. ArechClient2 has been delivered by loaders including HijackLoader/GHOSTPULSE and FakeBat, and through ClickFix paste-and-run lures, phishing, malicious software-download campaigns, malvertising, SEO poisoning, and trojanized MSIX packages. Campaigns have included sponsorship-themed phishing aimed at content creators and sector-specific lures targeting transportation and logistics organizations. ArechClient2 commonly uses dynamically retrieved command-and-control configuration, including dead-drop resolvers and, since at least 2025, EtherHiding through Binance Smart Chain smart contracts to obtain secondary command-and-control infrastructure.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
ClearFake has delivered multiple payloads over time, including ArechClient2 and LummaC2; most recently, we’ve observed ACR Stealer, which debuts in this month’s top 10.
If allowed to continue running beyond this stage, researchers have reported additional payloads including StealC and ArechClient2.
31 distinct techniques documented for this family, organized by ATT&CK tactic.
Fortinet identified actions including “running commands.”
“Researchers identified 29 commands supporting screen capture, remote shell access” and “cmd.exe [was] used by the uninstall routine.”
“The first malicious component decrypted assembly code hidden in a database file” and “decrypted the final malware from a second database file.”
“The payload also replaced readable code names with random ones and complicated its execution flow.”
“That intermediate code resolved 187 Windows functions dynamically, concealing their names until execution.”
The encrypted SectopRAT payload was embedded in legitimate-looking database files.
The encrypted SectopRAT payload was embedded in legitimate-looking database files.
The encrypted SectopRAT payload was embedded in legitimate-looking database files.
“[It] prepared the .NET runtime, and started the 64-bit SectopRAT payload directly in memory.”
“An uninstall command could delete the running executable after a six-second delay.”
sdkcra.dll lit des données chiffrées dans Activation.Desktop.db ... Le payload SectopRAT est lu depuis pool.db ... déchiffré en mémoire.
“The targets extended beyond browsers to Thunderbird, gaming applications, wallet extensions, and desktop cryptocurrency wallets.”
12 domaines de repli ... pour récupérer une IP C2 alternative via HTTP POST.
12 domaines de repli ... pour récupérer une IP C2 alternative via HTTP POST.
“If that failed, it contacted one of 12 backup endpoints to recover an alternative address through several decoding and decryption steps.”
“One command downloaded an additional browser extraction module.”
Il supporte 29 commandes C2 dont : Administration système distante, capture d’écran, shell distant; Gestion de processus et fichiers, redémarrage système.
205 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
19 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware that uses EtherHiding to pull C2 configuration from a smart contract, using AES decryption with a hardcoded key and embedded smart contract data.
An additional payload reportedly delivered in later stages of Scarlet Goldfinch activity.
Named malware/tool delivered via paste-and-run campaigns.
An infostealer profiled as a notable novel discovery by Elastic Security Labs.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.