logo

Lumma Stealer infection with Sectop RAT (ArechClient2), (Fri, Apr 17th)

ID: c3cb7ead-f283-566c-944f-74c743fa56a2

STIX ID: report--c3cb7ead-f283-566c-944f-74c743fa56a2

Feed Name: SANS ISC Diary

Threat Score
70/100

Date Published: 2026-04-17

Date Updated: 2026-04-19

...
...

This diary documents a Lumma Stealer infection obtained from a cracked-software site using a password-protected archive and an inflated, null-padded EXE, followed by deployment of Sectop RAT. The report includes the sample SHA256, file details, C2 domains discovered via sandboxing, and Sectop RAT C2 IPs/endpoints, illustrating a common cyber-crime distribution technique and providing actionable IOCs for detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.