Lumma Stealer infection with Sectop RAT (ArechClient2), (Fri, Apr 17th)
2026-04-17T01:23:48Z•6cb3c646f2c4fc07395a579fc7c517687dad9d305f02dde0b96223e40a6a79db
AI-model scanningArechClient2DShieldDVR compromiseEncystPHPFreePBXIoTLumma StealerMicrosoft Patch Tuesday April 2026Sectop RATclaudehuggingfacemalwareobfuscated JavaScriptopenclawphishingscanningvulnerabilitieswebshell
What happened
SANS ISC Diary (mid-April 2026) highlights multiple active threats: a reported Lumma Stealer infection delivering the Sectop RAT (ArechClient2); ongoing mass scans/probes for AI-model endpoints (claude, openclaw, huggingface, etc.) observed since 2026-03-10; large Microsoft Patch Tuesday (April 2026) with numerous fixes; scans and infections involving the EncystPHP webshell (noted targeting FreePBX systems); widespread compromise/abuse of DVRs in the wild; and phishing-delivered obfuscated JavaScript (sample SHA256:a8ba9ba93b4509a86e3d7dd40fd0652c2743e32277760c5f7942b788b74c5285) that is spars
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- 6cb3c646f2c4fc07395a579fc7c517687dad9d305f02dde0b96223e40a6a79db
- Enrichment time
- 2026-04-17T01:23:48Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.