SectopRAT, also known as ArechClient2, is a .NET remote-access trojan targeting Windows systems. It provides covert interactive access to compromised devices and incorporates extensive information-stealing functionality, including collection of browser logins, cookies, autofill records, payment-card data, FTP credentials, messaging-client data, personal files, and passwords. Its browser-focused collection and real-time browser-traffic proxying can expose authenticated web sessions and submitted credentials.
SectopRAT has been distributed as a follow-on payload by loaders including FakeBat and through FakeAgent malvertising campaigns that used sponsored search results and counterfeit Claude desktop-application download pages hosted through trusted web platforms. Observed delivery chains employed signed-binary DLL sideloading to execute staged payloads.
The malware employs anti-analysis and defense-evasion measures including VMProtect packing, virtual-machine and graphics-hardware checks, and shader-based payload decryption. It has used EtherHiding-style retrieval of command-and-control configuration from blockchain data, enabling operators to rotate infrastructure without relying solely on conventional domains. Observed infection chains also established persistence with elevated logon-triggered scheduled tasks and reduced endpoint visibility by adding Microsoft Defender exclusions. Public reporting has not confidently attributed FakeAgent SectopRAT activity to a specific known threat cluster.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The final payload was identified as SectopRAT, a remote access trojan with credential and data-theft behavior.
These malware families are frequently observed as initial infection vectors that deliver a wide range of secondary payloads, including SectopRAT, WarmCookie, HijackLoader, NetSupport RAT...
The PowerShell dropper ( bruce.php ) unpacks through five stages -- XOR decryption, reflective .NET assembly loading, AES-256-CBC decryption, Donut shellcode injection via raw NTDLL syscalls -- before deploying the final SectopRAT info-stealer targeting browser credentials, email clients, and cryptocurrency wallets.
Operators connect via C2, run system reconnaissance, and can drop SectopRAT as a secondary payload.
Operators connect via C2, run system reconnaissance, and can drop SectopRAT as a secondary payload.
30 distinct techniques documented for this family, organized by ATT&CK tactic.
Over the past few years, cybercriminals have increasingly used the drive-by download technique to distribute malware via user web browsing.
Traditional software supply chain compromise, the manipulation of source code or update/distribution mechanisms (T1195.002), remains rare.
In addition to likely cyber espionage incidents, we observed suspected financially motivated compromises with broader distribution. In two separate incidents threat actors compromised underlying software used in consumer-facing websites
Persistence on the system is achieved through another executable named DockerDesktop.exe, which installs a scheduled task.
PowerShell behavior: One or more execution delays via sleep command Connect to C2 to signal “start” Download payload from URL ending in .jpg Connect to C2 to signal “install” Load payload assembly using PowerShell
It downloads Redline Stealer binary disguised as a jpg file ... and SectopRAT/ArechClient ... Additional details on the PowerShell script can be seen in the annotated image below.
The victims had then downloaded malicious MSIX installer files (such as Zoom-x64.msix) which attempted to infect their systems
“The artifact visually impersonated a Claude Desktop / Claude Cowork download page” and the “claude.ai/share conversation [was] posing as an Apple Support guide.”
The SectopRAT payload ... is written to AppData\Local\Temp\ and injected into MsBuild.exe.
That stage checks graphics hardware and video memory to avoid sandboxes, then decrypts a hidden payload with a graphics shader instead of ordinary CPU code.
When launched, the package executes with elevated privileges then executes an embedded PowerShell script then drops and executes a legitimate copy of the Steam installer as a decoy.
Because these tools steal already-authenticated session cookies rather than passwords, the theft bypasses two-factor authentication and single sign-on entirely, letting attackers replay a victim’s Claude session.
The malware targets user passwords... browser logins and cookies, FTP credentials, data from messaging clients including Discord and Telegram, Steam, and VPN products.
Infostealer malware families including Vidar, Lumma (LummaC2), StealC, RedLine, and Acreed on Windows, along with Atomic Stealer on macOS, have been quietly copying saved passwords, browser cookies, and locally stored credentials from infected machines.
Among traffic flagged by ZT-IP, we observed the following suspicious HTTP GET request toward the destination IP address at 178.16.54[.]109... The observed request exhibits multiple variations, including sequential numeric GET paths (e.g., /1 through /6) and specific file downloads. | Malware samples often bypass DNS entirely, communicating directly to IP addresses instead. Our analysis of 4 million dynamic analysis reports indicates that almost half (45.32%) of malware samples with any command-and-control (C2) activity made at least one direct-to-IP (D2IP) address connection.
Both actors leverage SectopRAT's in-browser proxy capability to silently mirror all victim browser traffic to attacker-controlled servers in real time.
The research highlights malware that bypasses traditional DNS-based detection by communicating directly with hardcoded IP addresses instead of resolving domain names.
Huntress documented the FakeAgent campaign, in which attackers used a malicious public Claude Artifact hosted on the legitimate claude.ai domain to distribute a fake Claude Desktop installer... [which] ultimately delivered SectopRAT.
“The final payload is SectopRAT, a remote-access tool that can steal information and give attackers hidden control of an infected device.”
254 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
69 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A .NET remote-access trojan deployed through a fraudulent ClaudeDesktop.exe installer via DLL sideloading. It harvests browser credentials, payment-card data, cookies, and files.
Remote-access trojan that can steal passwords, files, and other sensitive information.
Remote-access trojan capable of stealing passwords, files, and other sensitive information.
A remote-access trojan delivered through a malicious Claude Artifact impersonating a Claude desktop application download page.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.