SectopRAT Malware Hides in Legitimate Software to Steal Browser Credentials and Crypto Wallets
SectopRAT hides in tampered legitimate software and steals browser credentials and crypto wallets.
FortiGuard analyzed a SectopRAT campaign, also known as ArechClient2, hidden in a tampered installation of legitimate digital-audio software from an Italian vendor. Investigators found no evidence of a vendor-distributed trojan or supply-chain compromise; the malicious folder was placed under C:\ProgramData after installation. A scheduled ReportDump.exe loads FrameworkBase.dll, whose import table was altered to pull in the sdkcra.dll loader, which decrypts the .NET RAT in memory. The malware contacts 98.142.252.140 on TCP port 15847 using AES-encrypted JSON commands, supports 29 functions including screen capture and shell execution, and its DeployBrowserKey module steals browser credentials, cookies, payment data, and cryptocurrency wallets.