SectopRAT is a Windows-focused .NET remote access trojan that has been active since at least 2019 and is also tracked under the alias ArechClient. It is used in financially motivated malware delivery ecosystems and has appeared both as a primary payload and as a secondary payload delivered by loaders, stealers, and social-engineering campaigns. Reported delivery chains include ClickFix lures, drive-by and SEO-poisoning activity, trojanized installers, malicious MSI packages abusing remote monitoring and management software, PowerShell droppers, and DLL side-loading chains. It has also been observed in broader malware distribution operations involving families such as DarkGate, HijackLoader, StealC, Dolphin Loader, and ACRStealer, and in infrastructure clusters associated with TAG-150 and ClearFake activity.
SectopRAT supports sustained remote access and hands-on-keyboard intrusion activity. Observed and reported capabilities include browser credential theft, cookie and session theft, theft of cryptocurrency wallet data, collection of email client data, software and system reconnaissance, clipboard monitoring, keylogging, screen or session monitoring, payload download and execution, process injection, and persistence. Multiple campaigns show strong defense-evasion tradecraft, including reflective or in-memory loading, AMSI bypass, direct system-call usage, shellcode-based staging, abuse of legitimate interpreters and signed binaries, and cleanup of dropped artifacts. Some variants retrieve command-and-control information dynamically, including through dead-drop style services.
Operationally, SectopRAT has been used to enable post-compromise actions such as persistence, lateral movement, and data exfiltration. It has been delivered in campaigns targeting general users as well as enterprise environments, including developer-focused SEO poisoning and ClickFix operations, and has been associated with abuse of legitimate websites, compromised WordPress sites, fake verification prompts, fake updates, and remote management tooling. The malware is part of a broader criminal ecosystem centered on credential theft, session hijacking, and follow-on access monetization.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
These malware families are frequently observed as initial infection vectors that deliver a wide range of secondary payloads, including SectopRAT, WarmCookie, HijackLoader, NetSupport RAT...
The PowerShell dropper ( bruce.php ) unpacks through five stages -- XOR decryption, reflective .NET assembly loading, AES-256-CBC decryption, Donut shellcode injection via raw NTDLL syscalls -- before deploying the final SectopRAT info-stealer targeting browser credentials, email clients, and cryptocurrency wallets.
Operators connect via C2, run system reconnaissance, and can drop SectopRAT as a secondary payload.
Operators connect via C2, run system reconnaissance, and can drop SectopRAT as a secondary payload.
38 distinct techniques documented for this family, organized by ATT&CK tactic.
The malware collects the victim’s external IP address and username, checks for an existing scheduled task named MSSecurity...
During routine malware analysis, I discovered a PowerShell-based dropper script being delivered from a malicious C2 domain... This script disables security controls, fetches 2 payloads (SectopRAT, HiJack Loader), exfiltrates data, and removes all traces of its execution.
Stage 3 -- Legitimate Python Binary : The ZIP extracts to a directory containing FNPLicensingService.exe -- which is actually a renamed, legitimately signed CPython 3.15 pythonw.exe... Stage 4 -- Obfuscated Python Loader : chrome_100_percent.pak ... is an ASCII text file containing obfuscated Python code.
Command and Scripting Interpreter: AutoIT ... Using AutoIT for possible automate script.
The malware collects the victim’s external IP address and username, checks for an existing scheduled task named MSSecurity...
The malware collects the victim’s external IP address and username, checks for an existing scheduled task named MSSecurity...
3=Yes - PE injection (MicrosoftEdgeUpdate or msbuild.exe) | One of the payloads extracted from the AutoIt script is DarkGate... 1=Yes - Process Hollowing injection enabled 3=Yes - PE injection (MicrosoftEdgeUpdate or msbuild.exe)
MITRE ATT&CK Mapping ... Defense Evasion Masquerading T1036.005 FNPLicensingService.exe (renamed pythonw.exe)
3=Yes - PE injection (MicrosoftEdgeUpdate or msbuild.exe) | One of the payloads extracted from the AutoIt script is DarkGate... 1=Yes - Process Hollowing injection enabled 3=Yes - PE injection (MicrosoftEdgeUpdate or msbuild.exe)
Before exiting, the malware removes: All downloaded ZIPs and folders The exfiltrated result file Itself via a helper script deleter.ps1
Architecture gate: Forces relaunch in 32-bit PowerShell via $env:WINDIR\SysWOW64\WindowsPowerShell\v1.0\powershell.exe... MITRE ATT&CK Mapping... T1218 32-bit PowerShell relaunch via SysWOW64.
Checks installed software on the system ... Looks up Uninstall key entries in the registry to enumerate software on the system.
The malware collects the victim’s external IP address... $externalIP = Invoke-RestMethod -Uri "http://ifconfig.me/ip"
The malware collects the victim’s external IP address and username... $username = $env:USERNAME
Enumerates connected drives ... System Information Discovery T1082
Enumerates connected drives ... Attempts to read the root path of hard drives other than the default C: drive.
Four contracts served distinct roles: Smart Contract A delivered the anti-analysis dispatcher...
The malware collects the victim’s external IP address and username, checks for an existing scheduled task named MSSecurity, and writes results to a result.txt file.
Victims saw a convincing fake Google reCAPTCHA overlay complete with an “I’m not a robot” checkbox. Clicking it triggered the ClickFix social engineering panel...
Clicking it triggered the ClickFix social engineering panel, which simultaneously injected a malicious command directly into the victim’s clipboard.
In SectopRAT samples, the malware first reaches out to Pastebin to retrieve the command and control address.
Legitimate hosting services abused for malware hosting/C2 ... Web Service T1102 ... pastebin.com
The script attempts to evade detection by creating Windows Defender exclusions for the entire C drive and two known processes often abused in malware campaigns. Add-MpPreference -ExclusionPath $folderPath Add-MpPreference -ExclusionProcess $processName Add-MpPreference -ExclusionProcess $processName1
190 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
48 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
RAT observé comme payload livré via ClickFix.
A remote access trojan listed among the malware payloads distributed through ClickFix campaigns.
A remote access trojan delivered as part of ClickFix payload rotation.
Named as an example of a RAT/backdoor used for long-term control in SEO-poisoning attack objectives.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.