#sectoprat
⚠️📢 Attackers modified files from legitimate audio software to hide and launch SectopRAT. The malware steals passwords, cookies, card details and crypto wallet data while giving attackers remote control of the PC.

Listen/Read: hackread.com/sectoprat-ab...

#SectopRAT #Windows #Malware #Cybersecurity
SectopRAT Abuses Legitimate Audio Software Files to Steal PC Data
FortiGuard found SectopRAT hidden in modified audio software files, using staged loading to steal browser data and remotely control infected Windows PCs.
hackread.com
September 25, 2026 at 10:54 AM
Hackers Deploy AsyncRAT and SectopRAT Using ScreenConnect Software on Windows
Hackers Deploy AsyncRAT and SectopRAT Using ScreenConnect Software on Windows
Cybercriminal groups are increasingly blending new and traditional techniques to steal sensitive information from unsuspecting users by deploying remote access tools (RATs) such as AsyncRAT and SectopRAT.
cybersecuritynews.com
December 24, 2024 at 5:30 AM
September 26, 2026 at 3:20 PM
SectopRAT Abuses Legitimate Audio Software Files to Steal PC Data

FortiGuard found SectopRAT hidden in modified audio software files, using staged loading to steal browser data and remotely control infected Windows PCs.
#hackernews #news
SectopRAT Abuses Legitimate Audio Software Files to Steal PC Data
FortiGuard found SectopRAT hidden in modified audio software files, using staged loading to steal browser data and remotely control infected Windows PCs.
hackread.com
September 26, 2026 at 10:18 AM
SectopRAT variant hides inside legit audio software via a tampered DLL - AES C2 from byte one. https://intel.threadlinqs.com/threat/TL-2026-2646 #ThreatIntel #SectopRAT #ArechClient2 #Rakhni
September 25, 2026 at 4:50 AM
~Fortinet~
Tampered Windows software loads SectopRAT for remote control and credential theft.
-
IOCs: 98[.]142[.]252[.]140:15847, 98[.]142[.]252[.]140:9000/wmglb, bsc-dataseed1[.]binance[.]org
-
#Malware #SectopRAT #ThreatIntel
SectopRAT Hidden in Legitimate Software
www.fortinet.com
September 24, 2026 at 4:15 PM
"Over 100 auto dealerships were being abused compliments of a supply chain attack of a shared video service unique to dealerships. When active, the attack presented dealership visitors with a ClickFix webpage which led to a SectopRAT malware."

rmceoin.github.io/malware-anal...
March 17, 2025 at 6:15 PM
SectopRAT Returns, Hiding Inside a Legitimate Application www.darkreading.com/cyberattacks...
SectopRAT Returns, Hiding Inside a Legitimate Application
The remote access Trojan (RAT) shows why organizations should monitor the behavior of applications rather than blindly trusting them, experts say.
www.darkreading.com
September 27, 2026 at 2:12 AM
SectopRAT (also known as ArechClient2) is a .NET-based remote access trojan (RAT) that provides a range of functions through multiple control commands.

Reference:
www.fortinet.com/blog/threat-...
Uncovering a SectopRAT Variant Embedded in Legitimate Software | FortiGuard Labs
Analysis of a SectopRAT variant hidden in tampered legitimate software that steals credentials and enables remote system control…
www.fortinet.com
September 25, 2026 at 10:51 PM
Uncovering a SectopRAT Variant Embedded in Legitimate Software https://packetstorm.news/news/view/44042 #news
September 25, 2026 at 5:07 PM
SectopRAT Returns, Hiding Inside a Legitimate Application
www.darkreading.com/cyberattacks...
SectopRAT Returns, Hiding Inside a Legitimate Application
The remote access Trojan (RAT) shows why organizations should monitor the behavior of applications rather than blindly trusting them, experts say.
www.darkreading.com
September 24, 2026 at 8:48 PM
The SectopRAT trojan is back, hiding in tampered legitimate software to steal credentials and control systems. ⚠️

Fortinet analysis reveals how the multi-stage Windows loader bypasses traditional scans and why behavioral monitoring is crucial.

#Cybersecurity #Malware #Windows
Fortinet researchers confirm SectopRAT attack on Windows users
The latest SectopRAT variant comes hidden within “tampered legitimate software that steals credentials and enables remote system control”.
www.techfinitive.com
September 25, 2026 at 7:20 AM
Collecting sensitive data from the victim’s device, capturing screens, remotely managing processes and files, controlling bots, and other forms of remote device management.
September 25, 2026 at 10:54 PM
Fake Claude app promoted by Bing ads pushes SectopRAT malware
Fake Claude app promoted by Bing ads pushes SectopRAT malware
A malvertising campaign on the Bing search service is pushing a fake Claude desktop app installer hosted on a legitimate Claude.ai domain to deliver the SectopRAT malware. [...]
www.bleepingcomputer.com
July 23, 2026 at 8:09 PM
SectopRAT、正規アプリケーション内に潜伏して復活

遠隔操作トロイの木馬SectopRATの最新活動が確認された。正規アプリケーションに偽装して配布される手口により、アプリケーションの振る舞い監視の重要性が指摘されている。組織は信頼だけに頼らず、ネットワーク活動の継続的な監視が必須となる。

#マルウェア #情報セキュリティ
SectopRAT、正規アプリケーション内に潜伏して復活
遠隔操作トロイの木馬SectopRATの最新活動が確認された。正規アプリケーションに偽装して配布される手口により、アプリケーションの振る舞い監視の重要性が指摘されている。組織は信頼だけに頼らず、ネットワーク活動の継続的な監視が必須となる。
www.darkreading.com
September 27, 2026 at 11:01 AM
2026-04-16 (Thursday): #pcap and #malware samples from the #LummaStealer infection with #SectopRAT ( #ArechClient2 ) that I documented in an ISC diary at isc.sans.edu/diary/Lumma+...
April 17, 2026 at 1:27 AM
🌟New report out today!🌟

Fake Zoom Ends in BlackSuit Ransomware

Analysis and reporting completed by @pigerlin, UC1 and @Miixxedup

Audio: Available on Spotify, Apple, YouTube and more!

thedfirreport.com/2025/03/31/f...
Fake Zoom Ends in BlackSuit Ransomware
Key Takeaways The threat actor gained initial access by a fake Zoom installer that used d3f@ckloader and IDAT loader to drop SectopRAT. After nine days of dwell time, the SectopRAT malware dropped …
thedfirreport.com
March 31, 2025 at 11:38 AM
ISC Diary: #LummaStealer infection with #SectopRAT (#ArechClient2) https://isc.sans.edu/diary/32904
April 17, 2026 at 12:30 AM
Work-related toot on an ongoing ClickFix / SecTopRat campaign. : infosec.exchange/@SophosXOps/... plus thread. I’ll repost some of the details here.
Sophos X-Ops (@SophosXOps@infosec.exchange)
Sophos MDR has observed two distinct social engineering campaigns using a technique referred to as ClickFix spiking during March. In both of these campaigns—one surging on March 2 and the other on Ma...
infosec.exchange
March 28, 2025 at 11:07 AM
2025-07-15 (Tuesday): #LummaStealer infection with #SecTopRAT. A #pcap of the #Lumma traffic and #SecTop #RAT activity, the #malware / artifacts from an infection, and the associated IOCs are available at www.malware-traffic-analysis.net/2025/07/15/i...
July 16, 2025 at 2:13 AM
SecTopRAT bundled in Chrome installer distributed via Google Ads

📖
www.malwarebytes.com/blog/news/20...

⚠️
sites[.]google[.]com/view/gfbtechd/
chrome[.]browser[.]com[.]de/GoogleChrome.exe

#malvertising #SecTopRAT
February 20, 2025 at 9:51 PM
SectopRATが復活、正規アプリケーションに潜伏

研究者らは、侵害後に活動するバックドア兼情報窃取型マルウェア「SectopRAT」の亜種が、イタリアのデジタルオーディオ企業が提供する正規ソフトウェアの中に隠されているのを発見しました。Fortinetが今週公開したレポートによると、攻撃者はソフトウェアベンダー自体を侵害したのではなく、正規アプリケーションが顧客システ
SectopRATが復活、正規アプリケーションに潜伏
研究者らは、侵害後に活動するバックドア兼情報窃取型マルウェア「SectopRAT」の亜種が、イタリアのデジタルオーディオ企業が提供する正規ソフトウェアの中に隠されているのを発見しました。Fortinetが今週公開したレポートによると、攻撃者はソフトウェアベンダー自体を侵害したのではなく、正規アプリケーションが顧客システ
blackhatnews.tokyo
September 24, 2026 at 8:53 PM