logo

Intelligence Insights: April 2025

ID: ba9a97da-3ab0-5726-be48-d98d7d9f87ad

STIX ID: report--ba9a97da-3ab0-5726-be48-d98d7d9f87ad

Feed Name: Red Canary

Threat Score
75/100

Date Published: 2025-04-24

Date Updated: 2026-04-29

Author: The Red Canary Team

...
...

Red Canary observed a March 2025 surge of HijackLoader delivering Arechclient2 (SectopRAT), a RAT with hidden secondary desktop and stealer functionality; operators used paste-and-run (fake CAPTCHA) and malvertising/SEO poisoning lures leading to encoded PowerShell execution, loader activity, C2 retrieval via pastebin and atypical TCP ports, and Arechclient2 has been associated with follow-on deployments of Cobalt Strike, Brute Ratel, and BlackSuit ransomware. The report highlights detection opportunities earlier in the chain (encoded PowerShell, network connections, executable writes) and lists observable IOCs and behaviors for defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.