SecTopRAT Malware — Analysis, Campaigns & Threat Activity

Threat entity extracted from intelligence sources

Frequency
13
occurrences
First Seen
November 27, 2025
Last Seen
August 31, 2026

Related Threat Clusters

  • ClearFake Campaign Uses Smart Contracts for C&C on BSC Testnet

    In May 2026, TrendAI™ Research reported on a cyber intrusion involving the ClearFake campaign, where threat actors utilized the EtherHiding technique to deliver payloads via smart contracts on the BNB Smart Chain…

    2 articles · Updated May 26, 2026
  • Infostealer Malware Hijacks Claude Sessions, Drains User Accounts

    Anthropic has alerted users that infostealer malware is compromising Claude accounts by hijacking active login sessions, allowing attackers to deplete usage limits without needing passwords or two-factor authentication.…

    32 articles · Updated August 31, 2026
  • Malvertising Campaign Distributes SectopRAT via Fake Claude Desktop App

    A malvertising campaign, dubbed FakeAgent, exploited Bing ads to distribute the SectopRAT malware through a fake Claude desktop app. Between July 21 and July 22, 2026, at least 29 organizations were compromised after…

    7 articles · Updated July 23, 2026
  • MacSync Infostealer Exploits Google Search for Claude Installation

    A malvertising campaign has emerged, using Google search results for Claude installation to deliver a macOS infostealer named MacSync. Victims are misled to a legitimate claude.ai shared conversation page, where they…

    2 articles · Updated August 19, 2026
  • Fake Claude Installer Delivers SectopRAT via DLL Sideloading

    A campaign using a counterfeit Claude desktop installer is targeting Windows systems, employing DLL sideloading and blockchain-based command-and-control to deploy the SectopRAT remote-access trojan. The attackers…

    2 articles · Updated August 26, 2026
  • UK Retail Cyber Attacks Show No Seasonal Spike Amid Holiday Concerns

    Analysis of cybersecurity incidents in the UK retail and manufacturing sectors reveals that 1,381 breaches occurred between Q3 2024 and Q2 2025, with no significant concentration around major shopping events. Security…

    61 articles · Updated November 28, 2025
  • LummaStealer Infections Rise Following CastleLoader Campaigns

    LummaStealer infections have surged due to social engineering campaigns utilizing the ClickFix technique to distribute CastleLoader malware. This infostealer, operating as a malware-as-a-service platform, had previously…

    7 articles · Updated February 11, 2026
  • Cyber Monday 2025: Surge in Online Scams Targeting Shoppers

    As Cyber Monday approaches, online shoppers are facing increased risks from cybercriminals exploiting the surge in digital purchases. Security experts warn of fraudulent websites, phishing emails, and insecure payment…

    7 articles · Updated November 21, 2025

Recent Intelligence Reports

  • Hackers Target Claude Accounts With Malware That Steals Login Sessions — Pymnts · August 31, 2026
  • Anthropic Warns Stolen Login Sessions Let Attackers Drain Claude Users' Usage Limits — Xenospectrum · August 31, 2026
  • Fake Claude Desktop Installer Deploys SectopRAT Using DLL Sideloading and Blockchain C2 — Gbhackers · August 26, 2026
  • MacSync Stealer: How a Google Search for Claude Led to a macOS Infostealer — Huntress · August 17, 2026
  • Huntress reports — www.huntress.com · July 25, 2026
  • Fake Claude app promoted by Bing ads pushes SectopRAT malware — Bleepingcomputer · July 23, 2026
  • Malicious actors weaponize Claude Artifacts to distribute malware — Feeds.4Sysops · July 23, 2026
  • How attackers hosted a fake Claude download page on the claude.ai domain — Feeds2.Feedburner · July 23, 2026

CVSS v3.1 Breakdown