SectopRAT Malware Hides in Legitimate Software to Steal Browser Credentials and Crypto Wallets
SectopRAT hides in tampered legitimate software and steals browser credentials and crypto wallets.
FortiGuard analyzed a SectopRAT campaign, also known as ArechClient2, hidden in a tampered installation of legitimate digital-audio software from an Italian vendor. Investigators found no evidence of a vendor-distributed trojan or supply-chain compromise; the malicious folder was placed under C:\ProgramData after installation. A scheduled ReportDump.exe loads FrameworkBase.dll, whose import table was altered to pull in the sdkcra.dll loader, which decrypts the .NET RAT in memory. The malware contacts 98.142.252.140 on TCP port 15847 using AES-encrypted JSON commands, supports 29 functions including screen capture and shell execution, and its DeployBrowserKey module steals browser credentials, cookies, payment data, and cryptocurrency wallets.
- Attackers modified an installed app under ProgramData, not a vendor build.
- Scheduled ReportDump.exe sideloads sdkcra.dll through tampered FrameworkBase.dll.
- The .NET payload, also called ArechClient2, supports 29 commands.
- It steals browser secrets and targets MetaMask, Exodus, Electrum, and other wallets.
- Primary C2 is 98.142.252.140 on TCP 15847, with Binance-related fallback domains.
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | binance.org | 2.252[.]140:15847 Backup Domain / URL hxxps://bsc-dataseed1.binance[.]org/ Backup Domain / URL hxxps://bsc-dataseed2.binance[.]org/ |
| url | http://98.142.252[ | ackup Domain / URL hxxps://bsc-dataseed4.binance[.]org/ URL hxxp://98.142.252[.]140:9000/wmglb Note: IP addresses and domains are intentio |
| url | https://bsc-dataseed1.binance[ | Address and Port 98.142.252[.]140:15847 Backup Domain / URL hxxps://bsc-dataseed1.binance[.]org/ Backup Domain / URL hxxps://bsc-dataseed2.binance[.]o |
| url | https://bsc-dataseed2.binance[ | RL hxxps://bsc-dataseed1.binance[.]org/ Backup Domain / URL hxxps://bsc-dataseed2.binance[.]org/ Backup Domain / URL hxxps://bsc-dataseed3.binance[.]o |
| url | https://bsc-dataseed3.binance[ | RL hxxps://bsc-dataseed2.binance[.]org/ Backup Domain / URL hxxps://bsc-dataseed3.binance[.]org/ Backup Domain / URL hxxps://bsc-dataseed4.binance[.]o |
| url | https://bsc-dataseed4.binance[ | RL hxxps://bsc-dataseed3.binance[.]org/ Backup Domain / URL hxxps://bsc-dataseed4.binance[.]org/ URL hxxp://98.142.252[.]140:9000/wmglb Note: IP addre |
Full article732 words · extracted from gbhackers.com · click to collapse
A newly analyzed SectopRAT campaign demonstrates how threat actors can weaponize trusted application components to conceal a full-featured remote access trojan and steal high-value data.
The investigation found no evidence that the software vendor distributed a trojanized build or that the incident stemmed from a supply-chain compromise.
Instead, attackers appear to have modified an existing software installation after deployment, placing the malicious folder under C:\ProgramData rather than the application’s ordinary installation path.
That distinction is critical: legitimate filenames and signed-looking program structures cannot be treated as proof of trust when DLL loading behavior has been altered.
The attack chain begins with ReportDump.exe, a legitimate-looking crash-reporting component configured to run through Windows Task Scheduler. When launched, it loads FrameworkBase.dll.
Attackers tampered with that DLL’s Import Address Table to add sdkcra.dll, a malicious loader, as an imported module.
This DLL sideloading-style execution path lets the implant run under the cover of a legitimate executable and its expected dependency chain.
The loader reads encrypted content from Activation.Desktop.db, decrypts it into assembly code, and abuses the Windows EnumSystemCodePagesW() callback parameter to execute that code.
The assembly then dynamically resolves 187 APIs by hash, frustrating static analysis and signature-based detection.

It subsequently reads encrypted data from pool.db, decrypts the payload in memory using a custom routine, initializes the .NET runtime, and invokes the SectopRAT entry point.
FortiGuard said in a report shared with GBhackers, the .NET-based malware, also known as ArechClient2, embedded within a tampered installation of legitimate digital audio workstation software from an Italian vendor.
SectopRAT Malware
The final payload is a 64-bit .NET executable protected through randomized names, control-flow flattening, and widespread use of the calli instruction, which invokes functions through pointers instead of normal method references.
These layers make reverse engineering substantially more difficult while also reducing the malware’s observable footprint on disk.
Once active, SectopRAT decrypts its command-and-control configuration and attempts to contact 98.142.252[.]140 over TCP port 15847.
The analysis of the dumped SectopRAT payload file in CFF Explorer, a PE analysis tool. Communications use AES encryption, with commands represented as JSON after decryption.

If its primary C2 is unavailable, the malware can request fallback infrastructure through 12 domains associated with Binance Smart Chain data endpoints, though Fortinet said it is unclear whether any of those domains were compromised.
The RAT supports 29 commands spanning remote administration, screen capture, process and file management, shell execution, rebooting, data export, plugin loading, and self-removal.
Its UnInstall command uses a delayed Windows shell command to delete the running payload after it exits, helping operators remove forensic evidence from a compromised host.
The most damaging functionality is triggered through the DeployBrowserKey command.
SectopRAT downloads an additional module, WbElevation.dll, then harvests saved credentials, URLs, cookies, autofill records, and stored payment-card information from Chromium-based browsers, Firefox-derived browsers, Microsoft Edge, Brave, Vivaldi, Yandex, and numerous other browser variants.

It also targets Thunderbird, Steam, Battle.net, NVIDIA GeForce Experience, and cryptocurrency wallets including MetaMask, Coinbase Wallet, TronLink, Atomic Wallet, Exodus, Electrum, and Daedalus Mainnet.
For defenders, suspicious scheduled tasks invoking ReportDump.exe, altered FrameworkBase.dll imports, and unexpected software folders under C:\ProgramData should be treated as priority hunting leads.
Organizations should also block or investigate connections to the reported C2 infrastructure, identify affected files, reset browser-stored credentials and active sessions, and review cryptocurrency wallet exposure where compromised endpoints were used.
Fortinet maps the activity to techniques including browser credential theft, encrypted C2, screen capture, obfuscated files, fallback channels, and indicator removal.
IOCs
| IOC Type | Indicator |
|---|---|
| C2 Server IP Address and Port | 98.142.252[.]140:15847 |
| Backup Domain / URL | hxxps://bsc-dataseed1.binance[.]org/ |
| Backup Domain / URL | hxxps://bsc-dataseed2.binance[.]org/ |
| Backup Domain / URL | hxxps://bsc-dataseed3.binance[.]org/ |
| Backup Domain / URL | hxxps://bsc-dataseed4.binance[.]org/ |
| URL | hxxp://98.142.252[.]140:9000/wmglb |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.