Fortinet Uncovers SectopRAT Variant Hidden Inside Tampered Legitimate Windows Software
Fortinet found SectopRAT hidden in tampered Italian audio software, using DLL tampering, scheduled tasks, and in-memory loading for remote control and credential theft.
FortiGuard Incident Response identified a SectopRAT (ArechClient2) variant on a compromised device, concealed inside a tampered legitimate digital audio workstation from an Italian developer. A modified FrameworkBase.dll imported a malicious component launched via Windows Task Scheduler, which decrypted assembly code from database files, dynamically resolved 187 Windows functions, and loaded the 64-bit payload entirely in memory. The RAT supports 29 commands including screen capture and remote shell, steals browser passwords, cookies, card data, Thunderbird data, and cryptocurrency wallet data, and uses AES-encrypted C2 with 12 backup endpoints including Binance BSC dataseed nodes. Fortinet found no evidence the developer distributed compromised software, pointing to file tampering rather than a confirmed supply-chain breach.