Malware
ArechClient2
- First Reported
- Sep 8, 2025
- Latest Reported
- Sep 24, 2026
Reported Context (3)
- SectopRAT (also known as ArechClient2) is a .NET-based remote access trojan (RAT) that provides a range of functions through multiple control commands. Fortinet Details SectopRAT Hidden in Legitimate Windows Software
- In these samples, SectopRAT or ArechClient2 was used as the final payload. CapFix Uses Evolving CapDoor Malware in Attacks on Russian Organizations
- Red Canary has previously observed this activity linked to the SecTopRAT/ArechClient2, a .NET RAT tool, which also inspired the following threat hunting query, which would detect this activity. DFIR Report Links Intrusion to Tools Used by Three Ransomware Groups
CVE (1)
Malware (9)
People (7)
Threat Actors (4)
MITRE ATT&CK (49)
Vendors (4)
Products (19)
Tools (8)
Industries (4)
Countries (2)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.