SectopRAT is a Windows remote access trojan with integrated information-stealing functionality. It has been observed in multiple malware delivery ecosystems and campaigns, including FakeBat loader activity, ClickFix operations, and the FakeAgent malvertising campaign that abused a fake Claude Desktop installer. The malware is also referred to as ArechClient2 in some reporting.
SectopRAT is designed to provide attackers with persistent remote access while harvesting sensitive user data. Reported theft targets include browser credentials, cookies, autofill data, payment card details, FTP credentials, messaging application data, Steam data, VPN-related data, personal files, and other personal information. Some reporting also describes Hidden Virtual Network Computing or in-browser proxy style functionality that enables real-time interaction with victim browser sessions, including mirroring visited pages and capturing submitted form data, which can facilitate session abuse and credential capture.
The malware has been associated with anti-analysis and defense-evasion measures including VMProtect packing, virtual machine and graphics hardware checks, and shader-based payload decryption in at least one delivery chain. SectopRAT infrastructure has also been described as using EtherHiding-style blockchain-backed retrieval of command-and-control information, and in other cases direct-to-IP communications that bypass DNS-based visibility and blocking controls.
Observed delivery has commonly relied on social engineering rather than exploitation. Documented vectors include malvertising, fake software installers, fake Claude Desktop lures, and ClickFix-style user-executed command chains. In one notable Windows campaign, signed binaries were abused for DLL sideloading to launch SectopRAT and establish persistence. SectopRAT has been deployed against multiple sectors, including educational institutions, and supports both credential theft and broader hands-on-keyboard post-compromise activity through remote access.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The final payload was identified as SectopRAT, a remote access trojan with credential and data-theft behavior.
These malware families are frequently observed as initial infection vectors that deliver a wide range of secondary payloads, including SectopRAT, WarmCookie, HijackLoader, NetSupport RAT...
The PowerShell dropper ( bruce.php ) unpacks through five stages -- XOR decryption, reflective .NET assembly loading, AES-256-CBC decryption, Donut shellcode injection via raw NTDLL syscalls -- before deploying the final SectopRAT info-stealer targeting browser credentials, email clients, and cryptocurrency wallets.
Operators connect via C2, run system reconnaissance, and can drop SectopRAT as a secondary payload.
Operators connect via C2, run system reconnaissance, and can drop SectopRAT as a secondary payload.
30 distinct techniques documented for this family, organized by ATT&CK tactic.
Over the past few years, cybercriminals have increasingly used the drive-by download technique to distribute malware via user web browsing.
Traditional software supply chain compromise, the manipulation of source code or update/distribution mechanisms (T1195.002), remains rare.
In addition to likely cyber espionage incidents, we observed suspected financially motivated compromises with broader distribution. In two separate incidents threat actors compromised underlying software used in consumer-facing websites
The infection chain starts with a simple Bing search for “CLAUDE DESKTOP APP.” Sponsored results fill the top of the page with lookalike download sites.
Persistence on the system is achieved through another executable named DockerDesktop.exe, which installs a scheduled task.
An identical copy called DockerDesktop.exe is later written as a scheduled task so the infection can restart after reboot.
PowerShell behavior: One or more execution delays via sleep command Connect to C2 to signal “start” Download payload from URL ending in .jpg Connect to C2 to signal “install” Load payload assembly using PowerShell
It downloads Redline Stealer binary disguised as a jpg file ... and SectopRAT/ArechClient ... Additional details on the PowerShell script can be seen in the annotated image below.
Persistence on the system is achieved through another executable named DockerDesktop.exe, which installs a scheduled task.
The domain names suggest an array of brands are impersonated in these attacks, including Microsoft, Zoom, Adobe, Steam, OpenAI
The SectopRAT payload ... is written to AppData\Local\Temp\ and injected into MsBuild.exe.
That stage checks graphics hardware and video memory to avoid sandboxes, then decrypts a hidden payload with a graphics shader instead of ordinary CPU code.
When launched, the package executes with elevated privileges then executes an embedded PowerShell script then drops and executes a legitimate copy of the Steam installer as a decoy.
The first, /churl (shown in Figure 4), relays every URL the victim visits, including: Authenticated session pages Single sign-on (SSO) redirects Learning management system content
Among traffic flagged by ZT-IP, we observed the following suspicious HTTP GET request toward the destination IP address at 178.16.54[.]109... The observed request exhibits multiple variations, including sequential numeric GET paths (e.g., /1 through /6) and specific file downloads. | Malware samples often bypass DNS entirely, communicating directly to IP addresses instead. Our analysis of 4 million dynamic analysis reports indicates that almost half (45.32%) of malware samples with any command-and-control (C2) activity made at least one direct-to-IP (D2IP) address connection.
Both actors leverage SectopRAT's in-browser proxy capability to silently mirror all victim browser traffic to attacker-controlled servers in real time.
The research highlights malware that bypasses traditional DNS-based detection by communicating directly with hardcoded IP addresses instead of resolving domain names.
FakeBat primarily aims to download and execute the next-stage payload, such as IcedID, Lumma, Redline, SmokeLoader, SectopRAT and Ursnif.
246 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
64 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remote access trojan mentioned only as a comparison to another fake Claude-themed campaign.
A remote access trojan used as the final payload in the FakeAgent malvertising campaign. It steals passwords, credit card data, personal information, and files, and uses VMProtect, virtual machine detection, and Ethereum blockchain-based command-and-control for evasion and attacker communications.
A remote access trojan highlighted for communicating directly with hard-coded IP addresses instead of using DNS, helping it evade DNS-based detection and blocking.
A remote access trojan used here against educational institutions, featuring an in-browser proxy that mirrors victim browser traffic and exfiltrates submitted form data including usernames and plaintext passwords over direct-to-IP connections.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.