logo

SectopRAT Gives Attackers Remote Access to Passwords, Credit Cards, Cookies and Corporate Files

ID: 3f3e7b99-52a0-5d8e-94b3-56b4de1852c1

STIX ID: report--3f3e7b99-52a0-5d8e-94b3-56b4de1852c1

Feed Name: GBHackers

Threat Score
80/100

Date Published: 2026-07-24

Date Updated: 2026-07-25

Author: Mayura Kathir

...
...

Huntress documented a malvertising campaign ("FakeAgent") that abused a trojanized Claude Desktop installer hosted as a Claude artifact to distribute SectopRAT, a .NET HVNC-capable RAT that steals browser credentials, cookies, payment data and files. The report details sophisticated TTPs—DLL sideloading, blockchain-based 'EtherHiding' C2 rotation, GPU-accelerated AES decryption and robust anti-VM/sandbox checks—provides multiple IOCs (domains, IP, BSC contracts), and notes at least 29 organizations impacted and ~7,100 artifact views prior to takedown.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.