Sectop RAT, also known as ArechClient2, is a Windows remote access trojan used as a follow-on payload in multi-stage intrusion chains. It has been observed alongside other commodity malware families including Lumma Stealer, Remcos RAT, NetSupport RAT, and StealC, indicating use in access monetization and post-compromise operations rather than as a standalone initial vector.
Observed delivery patterns show Sectop RAT arriving after earlier-stage malware or social-engineering-driven loaders. It has been deployed in ClickFix campaigns associated with SmartApeSG, also tracked as ZPHP and HANEYMANEY, where victims are tricked into executing malicious commands from fake CAPTCHA prompts on compromised websites. It has also appeared after cracked-software lures that first delivered Lumma Stealer, and it has been referenced as a possible follow-on payload in malicious MSIX/App Installer campaigns tied to Storm-1113 and Storm-1674. Earlier related loader activity has also been reported delivering Sectop RAT through fake software update themes.
On infected systems, Sectop RAT has been observed as a 64-bit Windows DLL executed through rundll32 and in delivery packages that rely on DLL sideloading via legitimate executables. These patterns indicate an emphasis on defense evasion and flexible staging. In documented SmartApeSG infections, Sectop RAT was delivered late in the chain after multiple other payloads had already established footholds, consistent with a role in sustained remote access and broader post-exploitation activity.
The malware targets Windows environments. Reported victim exposure includes users reached through compromised websites, fake verification workflows, pirated software lures, and malicious software-installation ecosystems. Its repeated appearance in financially motivated malware delivery operations suggests use for attacker-controlled remote access after initial compromise, often in campaigns that also pursue credential theft and data theft through companion malware.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In this previous campaign, the bitbucket folder contained additional malwares such as Remcos, Sectop RAT, Lumma Stealer, Mars Stealer, and Darktrack RAT.
The group has been linked to past campaigns that delivered dangerous tools including NetSupport RAT, Remcos RAT, StealC, and Sectop RAT.
The campaign, active as recently as March 24, 2026, delivered four separate malware payloads to a single infected host in one session: Remcos RAT, NetSupport RAT, StealC, and Sectop RAT, also known as ArechClient2.
The campaign, active as recently as March 24, 2026, delivered four separate malware payloads to a single infected host in one session: Remcos RAT, NetSupport RAT, StealC, and Sectop RAT, also known as ArechClient2.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
SmartApeSG works by injecting malicious scripts into legitimate but already-compromised websites. When a user visits one of these sites, they are redirected to a fake CAPTCHA page.
The outcome? A perfectly valid PE file... proves to be a legitimate AutoIT3 executable... After that, “Champion.exe.pif” executes “S”.
note the TCP Port 15647 and the “PowerShell get-process” calls for “avastui” and “avgui”.
shortly after we see a command-line task started with “cmd.exe /c cmd < 4”... after deobfuscating this, we get the following lines of cmd commands
In this incident, the SmartApeSG injected JavaScript behaved as a staged loader, and did not attempt to execute every action immediately.
Upon opening it, we are greeted by tons of gibberish... most of it is trash code, which is included to confuse... The script had 10255 lines in this style... the binary was strongly obfuscated using flow-dependent mutations and flow-dependent variables
the Execution Parent of our Sample is actually a file called “obs-installer-setupx64–29.685.zip”... threat actors register malicious websites, make them appear like official software pages
This did give further proof of a possible process injection through Process Hollowing: As initially expected, the AutoIT script injected some code into the legitimate “jsc.exe”.
One of the more technically notable aspects of this campaign is how it hides harmful code inside packages that also contain legitimate software.
We also see the creation of a TCP Client, which is used for C2 Communication... Prior Analysis of this threat has shown very similar TTP: A connection via TCP/IP, a Connection to Port 15647, JSON-based communication
Besides, the script was also responsible for the initial DNS Query that was observed.
26 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote access trojan used to take control of a victim’s computer remotely.
A remote access trojan associated with prior SmartApeSG campaigns.
Remote access trojan deployed in prior SmartApeSG-linked campaigns as a follow-on payload.
A remote access trojan delivered as follow-up malware after Lumma Stealer infection, installed and executed via rundll32 using the exported function LoadForm, and communicating with command-and-control infrastructure over HTTP and TCP.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.