#ArechClient2
SectopRAT variant hides inside legit audio software via a tampered DLL - AES C2 from byte one. https://intel.threadlinqs.com/threat/TL-2026-2646 #ThreatIntel #SectopRAT #ArechClient2 #Rakhni
September 25, 2026 at 4:50 AM
2026-04-16 (Thursday): #pcap and #malware samples from the #LummaStealer infection with #SectopRAT ( #ArechClient2 ) that I documented in an ISC diary at isc.sans.edu/diary/Lumma+...
April 17, 2026 at 1:27 AM
ISC Diary: #LummaStealer infection with #SectopRAT (#ArechClient2) https://isc.sans.edu/diary/32904
April 17, 2026 at 12:30 AM
SectopRAT (also known as ArechClient2) is a .NET-based remote access trojan (RAT) that provides a range of functions through multiple control commands.

Reference:
www.fortinet.com/blog/threat-...
Uncovering a SectopRAT Variant Embedded in Legitimate Software | FortiGuard Labs
Analysis of a SectopRAT variant hidden in tampered legitimate software that steals credentials and enables remote system control…
www.fortinet.com
September 25, 2026 at 10:51 PM
Elastic Security Labs has observed the ClickFix technique gaining popularity for multi-stage campaigns that deliver various malware using social engineering tactics. In one of these campaigns GHOSTPULSE loader is distributed and leads to LUMMA & ARECHCLIENT2. www.elastic.co/security-lab...
June 18, 2025 at 9:55 AM
2025-08-15 (Friday): Information from a social media post I wrote for my employer about a #LummaStealer infection leading to #SectopRAT (#ArechClient2). A #pcap of the infection traffc, along with the associated #malware and artifacts are available at www.malware-traffic-analysis.net/2025/08/15/i...
August 15, 2025 at 11:11 PM
Hackers 'Shellter' Various Stealers in Red Team Tool to Evade Detection
Hackers 'Shellter' Various Stealers in Red Team Tool to Evade Detection
Researchers have uncovered multiple campaigns spreading Lumma, Arechclient2, and Rhadamanthys malware by leveraging key features of the AV/EDR evasion framework.
www.darkreading.com
July 8, 2025 at 3:05 PM
Lumma Stealer to SectopRAT: A Deep Dive into the Latest Malware Chain Attack

Introduction: The cybersecurity landscape faces yet another sophisticated attack chain, where Lumma Stealer infections escalate into full SectopRAT (ArechClient2) deployments. This malware campaign leverages deceptive…
Lumma Stealer to SectopRAT: A Deep Dive into the Latest Malware Chain Attack
Introduction: The cybersecurity landscape faces yet another sophisticated attack chain, where Lumma Stealer infections escalate into full SectopRAT (ArechClient2) deployments. This malware campaign leverages deceptive downloads, persistence mechanisms, and command-and-control (C2) infrastructure to compromise victim machines. Below, we dissect the attack flow, provide actionable detection/mitigation steps, and analyze its implications. Learning Objectives: Understand the infection chain from Lumma Stealer to SectopRAT.
undercodetesting.com
August 15, 2025 at 10:22 PM
Highly Obfuscated .NET sectopRAT Mimic as Chrome Extension
Highly Obfuscated .NET sectopRAT Mimic as Chrome Extension
The emergence of a highly obfuscated .NET-based Remote Access Trojan (RAT) known as sectopRAT, disguised as a legitimate Google Chrome extension has been revealed in a recent analysis. This malicious software, also identified as Arechclient2, demonstrates advanced obfuscation techniques and sophisticated functionalities aimed at data theft. SectopRAT is written in .NET and employs the calli obfuscator, a technique that complicates reverse engineering by obscuring the code’s logic. sectopRAT identified using Detect It Easy (Source – Malwr-Analysis) Despite attempts to deobfuscate the malware using tools like CalliFixer, the code remained challenging to analyze. Attempts to deobfuscate the code using CalliFixer (Source – Malwr-Analysis) The sample analyzed had notable characteristics, including a file hash of EED3542190002FFB5AE2764B3BA7393B and a file size of 768KB. It was detected by 61 out of 72 antivirus engines on VirusTotal. Upon execution, sectopRAT connects to a Command and Control (C2) server at 91.202.233.18 over ports 9000 and 15647, enabling remote attackers to control infected systems . Here the Malware Analyst, Anurag from Malwr-Analysis noted that the malware masquerades as a Google Chrome extension named “Google Docs,” deceiving users into installing it. Dynamic Analysis: Malicious Chrome Extension The malicious extension consists of three key files: manifest.json , content.js , and background.js . These components work together to perform data exfiltration. The manifest.json file declares the extension’s name and permissions, misleadingly claiming to provide offline editing for Google Docs while granting extensive permissions that allow script injection across all web pages. Malicious Chrome Extension Disguised as Google Docs (Source – Malwr-Analysis) The content.js script injects event listeners into every webpage visited by the user, capturing sensitive inputs such as usernames, passwords, credit card details, and form data. Decompiled code (Source – Malwr-Analysis) Meanwhile, background.js functions as an intermediary to bypass browser security policies, transmitting the stolen data from content.js to the command-and-control (C2) server. The extension’s behavior was observed during sandbox analysis, where it monitored user input fields across websites and relayed the captured data to the attacker-controlled server. SectopRAT’s ability to masquerade as a legitimate Chrome extension which shows the increasing sophistication of browser-based threats. With capabilities to extract stored credentials, monitor user activity, and exfiltrate sensitive data, it poses a significant cybersecurity risk. To mitigate this threat, network traffic to 91.202.233.18 should be blocked, installed browser extensions should be regularly audited, behavioral-based threat detection tools should be employed, and the execution of untrusted .NET applications should be restricted. IOCs The following indicators of compromise (IoCs) were identified:- C2 Server : 91.202.233.18 File Hash : EED3542190002FFB5AE2764B3BA7393B Malicious URL : https://pastebin.com/raw/wikwTRQc Investigate Real-World Malicious Links & Phishing Attacks With  Threat Intelligence Lookup  -  Try for Free The post Highly Obfuscated .NET sectopRAT Mimic as Chrome Extension appeared first on Cyber Security News .
cybersecuritynews.com
February 19, 2025 at 8:16 AM
A fake Claude Desktop installer served off real claude.ai side-loads SectopRAT and hides C2 on the blockchain. https://intel.threadlinqs.com/threat/TL-2026-1669 #ThreatIntel #SectopRAT #Arechclient2 #Stealc
July 24, 2026 at 1:41 PM
A fake Claude Desktop app pushed via Bing ads hides its C2 on-chain and decrypts itself on your GPU. https://intel.threadlinqs.com/threat/TL-2026-1662 #ThreatIntel #SectopRAT #VMProtect #FakeAgent
July 23, 2026 at 8:10 PM
Fake PDFCandy sites using Google Ads spread ArechClient2 malware. #malware #phishing #cybersecurity
Fake PDFCandy Websites Distribute ArechClient2 Malware
Fake PDFCandy sites using Google Ads spread ArechClient2 malware. #malware #phishing #cybersecurity
gbhackers.com
April 17, 2025 at 12:27 PM
ClickFix, dove il comando malevolo viene lanciato direttamente dalla vittima

Leggi qui: ift.tt/kjq3ncv
ift.tt/Ltah4Gi
ClickFix, dove il comando malevolo viene lanciato direttamente dalla vittima
L’analisi condotta da Elastic Security Labs sulla campagna denominata ClickFix, culminata nella distribuzione di infostealer come ARECHCLIENT2 tramite il loader…
ift.tt
June 20, 2025 at 11:55 AM
We identified this malware as #HijackLoader, with the final payload being Arechclient2 RAT. This combination has been previously observed by RedCanary here: x.com/redcanary/st...

A complete analysis of HijackLoader is beyond the scope of this thread, but stay tuned for long-form content 👀

6/8🧵
Red Canary on X: "Last month we noticed a surprising payload combination in some paste and run (aka ClickFix and fakeCAPTCHA) campaigns: HijackLoader dropping the Arechclient2 RAT. 🐀 💡 Learn more about Arechclient2 and the rest of the month's top 10 threats in our April Intelligence Insights: https://t.co/TRLwhgIknY" / X
Last month we noticed a surprising payload combination in some paste and run (aka ClickFix and fakeCAPTCHA) campaigns: HijackLoader dropping the Arechclient2 RAT. 🐀 💡 Learn more about Arechclient2 and the rest of the month's top 10 threats in our April Intelligence Insights: https://t.co/TRLwhgIknY
x.com
April 25, 2025 at 3:58 PM
SmartApeSG ClickFix Campaign Delivers Remcos, NetSupport RAT, StealC and Sectop RAT
SmartApeSG ClickFix Campaign Delivers Remcos, NetSupport RAT, StealC and Sectop RAT
A threat campaign known as SmartApeSG — also tracked under the names ZPHP and HANEYMANEY — has been observed pushing multiple strains of malware through a social engineering technique called ClickFix. The campaign, active as recently as March 24, 2026, delivered four separate malware payloads to a single infected host in one session: Remcos RAT, NetSupport RAT, StealC, and Sectop RAT, also known as ArechClient2. This wave of activity shows how attackers stack multiple tools inside one campaign to maximize damage from a single user mistake. SmartApeSG works by injecting malicious scripts into legitimate but already-compromised websites. When a user visits one of these sites, they are redirected to a fake CAPTCHA page — a page that looks like a routine verification check but is designed to trick the user into running a harmful script. Fake CAPTCHA page (Source – Internet Storm Center) The compromised website silently loads the injected script in the background, setting up the deceptive page that the visitor encounters. Internet Storm Center researchers identified this latest SmartApeSG wave on March 24, 2026, documenting how the campaign delivered each payload in a staged sequence over several hours. The fake CAPTCHA page carries ClickFix instructions that silently copy a malicious script into the user’s clipboard, prompting the victim to paste and execute it manually through the Windows Run dialog box. Once the user follows those steps, the infection chain kicks off and runs without obvious warning signs on the compromised machine. The impact of this campaign is serious because it does not stop at one malware family. Starting at 17:12 UTC, Remcos RAT traffic was detected just one minute after the ClickFix script ran. NetSupport RAT followed only four minutes later. Then, roughly one hour after that, StealC began sending data to its own command-and-control server, followed by Sectop RAT approximately one hour and eighteen minutes after StealC appeared. This staggered delivery gives defenders a narrow window to catch the infection before multiple threats are already running in parallel on the same system. The overall payload mix — a keylogger-capable RAT, a remote support tool turned against users, a credential stealer, and a second RAT — makes clear that SmartApeSG is built to give attackers deep and varied access to a victim machine from a single infection event. DLL Side-Loading: How the Malware Hides in Plain Sight One of the more technically notable aspects of this campaign is how it hides harmful code inside packages that also contain legitimate software. The archive files for Remcos RAT, StealC, and Sectop RAT all rely on a technique called DLL side-loading, where a trusted and recognized executable file is used to quietly load a malicious DLL file alongside it. Since the main executable appears clean and familiar, many security tools may not immediately flag what is happening. NetSupport RAT takes a different path — it is itself a real and legitimate remote support application, but in this campaign, it has been configured to connect to an attacker-controlled server rather than a trusted one. Network traffic filtered in Wireshark reveals the distinct connections each malware strain makes to its own command-and-control server. The HTA file that starts the Remcos RAT download is pulled from  urotypos[.]com  and saved locally as  post.hta  before it runs. Critically, the ClickFix script deletes this HTA file right after executing it, making forensic investigation harder for response teams who do not catch the infection quickly. Organizations are strongly advised to block the domains  urotypos[.]com  and  fresicrto[.]top  at the DNS and firewall level, and to monitor outbound traffic toward  95.142.45[.]231 ,  185.163.47[.]220 ,  89.46.38[.]100 , and  195.85.115[.]11 . Employees should be trained to never paste or run clipboard content prompted by any website. Security teams should also watch for unexpected HTA file execution and unusual DLL loading activity within user-accessible directories such as AppData and ProgramData. Follow us on  Google News ,  LinkedIn , and  X  to Get More Instant Updates ,  Set CSN as a Preferred Source in  Google . The post SmartApeSG ClickFix Campaign Delivers Remcos, NetSupport RAT, StealC and Sectop RAT appeared first on Cyber Security News .
cybersecuritynews.com
March 25, 2026 at 4:32 PM
Malware Campaigns Target Crypto Wallets with Fake PDF Conversion Software

Malware campaigns use fake PDFs as vectors to sneak malicious PowerShell commands into the machine, allowing attackers to steal crypto wallets, hijack browser credentials and information. Following last month's FBI alert,…
Malware Campaigns Target Crypto Wallets with Fake PDF Conversion Software
Malware campaigns use fake PDFs as vectors to sneak malicious PowerShell commands into the machine, allowing attackers to steal crypto wallets, hijack browser credentials and information. Following last month's FBI alert, the CloudSek Security Research team conducted an investigation to reveal more details about the attack. The goal is to run a PowerShell command that will trick users into installing ArechClient2 Malware, a variant of Sectoprat, a family known to harvest sensitive data from victims.
earlybirdsinvest.com
April 24, 2025 at 3:48 AM
Lumma Stealer infection with Sectop RAT (ArechClient2), (Fri, Apr 17th)
#hackernews #news
Lumma Stealer infection with Sectop RAT (ArechClient2), (Fri, Apr 17th)
isc.sans.edu
April 17, 2026 at 9:39 PM
SmartApeSG campaign pushes Remcos RAT, NetSupport RAT, StealC, and Sectop RAT (ArechClient2), (Wed, Mar 25th)
#hackernews #news
SmartApeSG campaign pushes Remcos RAT, NetSupport RAT, StealC, and Sectop RAT (ArechClient2), (Wed, Mar 25th)
isc.sans.edu
March 25, 2026 at 10:25 PM
Fake PDFCandy File Converter Websites Spread Malware

CloudSEK uncovers a sophisticated malware campaign where attackers impersonate PDFCandy.com to distribute the ArechClient2 information stealer. Learn how…

#hackernews #news
Fake PDFCandy File Converter Websites Spread Malware
CloudSEK uncovers a sophisticated malware campaign where attackers impersonate PDFCandy.com to distribute the ArechClient2 information stealer. Learn how…
hackread.com
April 16, 2025 at 5:33 PM
Lumma Stealer Infection Escalates Into Sectop RAT: A Deep Dive Into a Multi-Stage Malware Trap

Introduction Cybercriminals are constantly refining their methods, blending social engineering with technical evasion to compromise unsuspecting users. One of the most effective entry points remains…
Lumma Stealer Infection Escalates Into Sectop RAT: A Deep Dive Into a Multi-Stage Malware Trap
Introduction Cybercriminals are constantly refining their methods, blending social engineering with technical evasion to compromise unsuspecting users. One of the most effective entry points remains deceptively simple: cracked software downloads. What appears to be a free version of a premium tool often hides a far more costly consequence. This case highlights a real-world infection chain where Lumma Stealer acts as the initial payload, followed by the deployment of Sectop RAT (ArechClient2).
undercodenews.com
April 17, 2026 at 12:58 AM
Arechclient2 (sectopRAT) Analysis – A Highly Obfuscated .NET RAT with Malicious Chrome Extension
Arechclient2 (sectopRAT) Analysis – A Highly Obfuscated .NET RAT with Malicious Chrome Extension
malwr-analysis.com
February 18, 2025 at 12:24 PM