logo

SecTopRAT bundled in Chrome installer distributed via Google Ads

ID: 94c759b0-a337-56e4-92d1-dc5a413f3628

STIX ID: report--94c759b0-a337-56e4-92d1-dc5a413f3628

Feed Name: Malwarebytes Blog

Threat Score
70/100

Date Published: 2025-02-20

Date Updated: 2026-04-28

...
...

Malwarebytes documents an active campaign that used fraudulent Google Ads linking to Google Sites to deliver a fake Google Chrome installer which retrieves and decrypts a payload that installs SecTopRAT (a RAT with stealer functionality); the malware injects into MSBuild.exe, disables Defender scanning via a PowerShell exclusion, contacts C2 at 45.141.84.208, and finally installs the legitimate Chrome to avoid suspicion. The blog includes detailed IOCs (malicious sites, filenames, hashes, payload host and C2) and notes that Malwarebytes protections block the ad and detect the payload.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.