2025-08-15: Lumma Stealer infection with SectopRAT

2025-08-15 (FRIDAY): LUMMA STEALER INFECTION WITH SECTOP RAT (ARECHCLIENT2)—————————————————————————NOTES:* Zip files are password-protected. Of note, this site has a new password scheme. For the password, see the ‘about’ page of this website.REFERENCES:* * * ASSOCIATED FILES:* 3.7 kB (3,732 bytes)* 22.1 MB (22,115,013 bytes)* 20.5 MB (20,499,729 bytes)[Click here](../../../index.html) to return to the main page.

Related Tags:
LummaStealer

NAICS: 54 – Professional

Scientific

Technical Services

NAICS: 541 – Professional

Scientific

Technical Services

NAICS: 518 – Computing Infrastructure Providers

Data Processing

Web Hosting

Related Services

NAICS: 51 – Information

Blog: Malware Traffic Analysis

System Information Discovery

Associated Indicators:
https://github.com/PaloAltoNetworks/Unit42-timely-threat-intel/blob/main/2025-08-15-IOCs-for-Lumma-Stealer-infection-with-Sectop-RAT.txt

2025-08-15-iocs-for-lumma-stealer-infection-with-sectop-rat.txt.zip

2025-08-15-lumma-stealer-infection-with-sectop-rat.pcap.zip

2025-08-15-malware-from-lumma-stealer-with-sectoprat-infection.zip