Fortinet Uncovers SectopRAT Variant Hidden Inside Tampered Legitimate Windows Software
Fortinet found SectopRAT hidden in tampered Italian audio software, using DLL tampering, scheduled tasks, and in-memory loading for remote control and credential theft.
FortiGuard Incident Response identified a SectopRAT (ArechClient2) variant on a compromised device, concealed inside a tampered legitimate digital audio workstation from an Italian developer. A modified FrameworkBase.dll imported a malicious component launched via Windows Task Scheduler, which decrypted assembly code from database files, dynamically resolved 187 Windows functions, and loaded the 64-bit payload entirely in memory. The RAT supports 29 commands including screen capture and remote shell, steals browser passwords, cookies, card data, Thunderbird data, and cryptocurrency wallet data, and uses AES-encrypted C2 with 12 backup endpoints including Binance BSC dataseed nodes. Fortinet found no evidence the developer distributed compromised software, pointing to file tampering rather than a confirmed supply-chain breach.
- Tampered FrameworkBase.dll plus a scheduled task launched the staged SectopRAT loader.
- Loader decrypted payload from database files and ran it fully in memory.
- 29 commands enable remote shell, screen capture, and file/process control.
- Steals browser credentials, cookies, card data, Thunderbird, and wallet data.
- AES-encrypted C2 at 98.142.252[.]140:15847 with 12 fallback endpoints.
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | binance.org | server and TCP port. Backup endpoint hxxps://bsc-dataseed1.binance[.]org/ Fallback endpoint used to recover a controller address; |
| domain | defibit.io | mise not established. Backup endpoint hxxps://bsc-dataseed1.defibit[.]io/ Fallback endpoint used to recover a controller address; |
| domain | ninicoin.io | mise not established. Backup endpoint hxxps://bsc-dataseed1.ninicoin[.]io/ Fallback endpoint used to recover a controller address; |
| sha256 | 37fcbcb21d16866784050682c58424c91d3a736f6fd599271fa6e53cf5ca8a92 | B9E4F390B937788B Tampered FrameworkBase.dll sample. SHA-256 37FCBCB21D16866784050682C58424C91D3A736F6FD599271FA6E53CF5CA8A92 Malicious sdkcra.dll sample. SHA-256 EFA07701570983909EF923 |
| sha256 | 48d3ecbb9e0b6babe6e53e2082a076bad07ef61ccd98dcc8b9e4f390b937788b | n serving the additional browser extraction module. SHA-256 48D3ECBB9E0B6BABE6E53E2082A076BAD07EF61CCD98DCC8B9E4F390B937788B Tampered FrameworkBase.dll sample. SHA-256 37FCBCB21D168667 |
| sha256 | 95f6abd3c43ef4b33cd61d054527233dd2ce705804d44a04be96cfb73bb52e3a |
Full article1,140 words · extracted from cybersecuritynews.com · click to collapse
A SectopRAT variant has been found hidden inside tampered Windows software, allowing attackers to control an infected computer and steal sensitive information.
The intrusion used legitimate application components as cover, with encrypted files concealing the malware until it was loaded into memory.
The affected program came from an Italian developer known for a long-running digital audio workstation. Attackers modified its supporting files and arranged automatic execution through a scheduled task.
The investigation did not establish how the altered software first reached the victim’s computer. Researchers from Fortinet’s FortiGuard Incident Response team identified the variant while investigating a compromised device.
Fortinet said in a report shared with Cyber Security News (CSN) that the malware combined a staged loader with extensive remote-control and information-stealing capabilities.
Also known as ArechClient2, SectopRAT is an existing malware family rather than a newly discovered threat. Earlier malicious search advertising campaigns have delivered it through deceptive downloads.
.webp)
This investigation documents another concealment method, but does not establish a connection to those campaigns or quantify wider infections.
Fortinet Uncovers SectopRAT Variant
The attackers changed a legitimate supporting library so it would import an additional malicious component when the application’s reporting executable started.
Windows Task Scheduler launched that executable automatically, giving the modified software a way to activate without repeated user interaction.
Investigators found the altered application folder outside its normal installation location. Crucially, Fortinet found no evidence that the developer distributed compromised software.
The available evidence points to tampering with legitimate files, not a confirmed breach of the vendor’s software supply chain. The first malicious component decrypted assembly code hidden in a database file.
.webp)
It then passed that code through another library and abused a Windows callback function, which normally processes system information, to execute the decrypted instructions instead.
That intermediate code resolved 187 Windows functions dynamically, concealing their names until execution. It decrypted the final malware from a second database file, prepared the .NET runtime, and started the 64-bit SectopRAT payload directly in memory.
Comparable in-memory malware loading techniques have appeared in other investigations, including Sauron Loader. Here, encryption, indirect calls, and multiple loading stages made the working payload less obvious than a standalone malicious executable sitting openly in an application folder.
The payload also replaced readable code names with random ones and complicated its execution flow. These changes layered additional obstacles over a loader already designed to conceal the final program during normal inspection.
Frequent calls through method pointers further hindered reverse engineering, making it harder for analysts to follow the malware’s logic and identify its functions.
Remote control
Once active, SectopRAT decrypted its controller’s address from embedded resources and attempted a connection. If that failed, it contacted one of 12 backup endpoints to recover an alternative address through several decoding and decryption steps.
Fortinet noted that these endpoints appeared related to Binance Coin infrastructure, but could not establish whether attackers had compromised them. Their use as fallback channels should not be confused with proof that their operators participated in the intrusion.
All traffic between the malware and its controller was AES-encrypted. Researchers identified 29 commands supporting screen capture, remote shell access, file and process management, computer restarts, and other administrative actions that effectively placed the device under outside control.
One command downloaded an additional browser extraction module. The malware collected saved passwords, associated website addresses, autofill records, payment-card information, and cookies. Similar browser credential theft campaigns show why a single infected device can expose several valuable accounts at once.
The targets extended beyond browsers to Thunderbird, gaming applications, wallet extensions, and desktop cryptocurrency wallets. Collected information was packaged as structured data, encrypted, and sent to the controller. An uninstall command could delete the running executable after a six-second delay.
Fortinet recommends security-awareness training to help users recognize phishing and other suspicious content, alongside seeking incident-response assistance when compromise is suspected.
Its published indicators provide investigation leads, but legitimate filenames and shared infrastructure require context rather than automatic assumptions of malicious ownership.
Indicators of compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| C2 IP and port | 98.142.252[.]140:15847 | Hardcoded command-and-control server and TCP port. |
| Backup endpoint | hxxps://bsc-dataseed1.binance[.]org/ | Fallback endpoint used to recover a controller address; compromise not established. |
| Backup endpoint | hxxps://bsc-dataseed2.binance[.]org/ | Fallback endpoint used to recover a controller address; compromise not established. |
| Backup endpoint | hxxps://bsc-dataseed3.binance[.]org/ | Fallback endpoint used to recover a controller address; compromise not established. |
| Backup endpoint | hxxps://bsc-dataseed4.binance[.]org/ | Fallback endpoint used to recover a controller address; compromise not established. |
| Backup endpoint | hxxps://bsc-dataseed1.defibit[.]io/ | Fallback endpoint used to recover a controller address; compromise not established. |
| Backup endpoint | hxxps://bsc-dataseed2.defibit[.]io/ | Fallback endpoint used to recover a controller address; compromise not established. |
| Backup endpoint | hxxps://bsc-dataseed3.defibit[.]io/ | Fallback endpoint used to recover a controller address; compromise not established. |
| Backup endpoint | hxxps://bsc-dataseed4.defibit[.]io/ | Fallback endpoint used to recover a controller address; compromise not established. |
| Backup endpoint | hxxps://bsc-dataseed1.ninicoin[.]io/ | Fallback endpoint used to recover a controller address; compromise not established. |
| Backup endpoint | hxxps://bsc-dataseed2.ninicoin[.]io/ | Fallback endpoint used to recover a controller address; compromise not established. |
| Backup endpoint | hxxps://bsc-dataseed3.ninicoin[.]io/ | Fallback endpoint used to recover a controller address; compromise not established. |
| Backup endpoint | hxxps://bsc-dataseed4.ninicoin[.]io/ | Fallback endpoint used to recover a controller address; compromise not established. |
| Download URL | hxxp://98.142.252[.]140:9000/wmglb | Location serving the additional browser extraction module. |
| SHA-256 | 48D3ECBB9E0B6BABE6E53E2082A076BAD07EF61CCD98DCC8B9E4F390B937788B | Tampered FrameworkBase.dll sample. |
| SHA-256 | 37FCBCB21D16866784050682C58424C91D3A736F6FD599271FA6E53CF5CA8A92 | Malicious sdkcra.dll sample. |
| SHA-256 | EFA07701570983909EF923EA79BB032F19FD9DAC0B819FA0E4F6B1161A4CC221 | Activation.Desktop.db containing encrypted assembly code. |
| SHA-256 | 95F6ABD3C43EF4B33CD61D054527233DD2CE705804D44A04BE96CFB73BB52E3A | pool.db containing the encrypted SectopRAT payload. |
| File name | ReportDump.exe | Legitimate reporting component launched through a scheduled task; name alone does not establish compromise. |
| File name | FrameworkBase.dll | Legitimate library modified to import the malicious loader. |
| File name | sdkcra.dll | Malicious entry library that begins payload extraction. |
| File name | Activation.Desktop.db | Database file holding encrypted intermediate code. |
| File name | pool.db | Database file holding the encrypted final payload. |
| File name | WbElevation.dll | Downloaded module assisting browser data extraction. |
| File name | SDL3.dll | Library whose exported file-reading function is used during loading; contextual artifact. |
| File name | stp_aim_x64_vc15.dll | Library used to invoke the Windows callback that executes decrypted code; contextual artifact. |
| File name | mscoreei.dll | .NET runtime component loaded before payload execution; legitimate contextual artifact. |
| File name | clr.dll | .NET runtime component loaded before payload execution; legitimate contextual artifact. |
| File name | cmd.exe | Legitimate Windows command interpreter used by the uninstall routine. |
| Directory | C:\ProgramData | Location containing the tampered application folder, outside the software’s normal installation directory. |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.