Remote Access Trojan

ArechClient2

First seen: 2019-01 • Status: active

Currently Active Threat

ArechClient2 is a remote access tool that also steals information. It spreads through spam emails.

Overview

ArechClient2/SectopRAT is a .NET RAT with information stealing capabilities. It is commonly distributed via malspam.

Also Known As

SectopRAT

How It Spreads

  • Malspam
  • Exploit kits

What It Does

  • Remote access
  • Information stealing

Is your business exposed?

Target Platforms

Windows

Detection Tips

  • Monitor for .NET RAT signatures

MITRE ATT&CK Techniques

T1219, T1555

If You're Infected

  1. 1.

    Full malware removal

Related Malware

Asyncrat

Is your business exposed?

Check if your company data is circulating on the dark web

Free scan • No credit card required