Fortinet Uncovers SectopRAT Variant Hidden Inside Tampered Legitimate Windows Software

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


A SectopRAT variant has been found hidden inside tampered Windows software, allowing attackers to control an infected computer and steal sensitive information.

The intrusion used legitimate application components as cover, with encrypted files concealing the malware until it was loaded into memory.

The affected program came from an Italian developer known for a long-running digital audio workstation. Attackers modified its supporting files and arranged automatic execution through a scheduled task.

The investigation did not establish how the altered software first reached the victim’s computer. Researchers from Fortinet’s FortiGuard Incident Response team identified the variant while investigating a compromised device.

Fortinet said in a report shared with Cyber Security News (CSN) that the malware combined a staged loader with extensive remote-control and information-stealing capabilities.

Also known as ArechClient2, SectopRAT is an existing malware family rather than a newly discovered threat. Earlier malicious search advertising campaigns have delivered it through deceptive downloads.

The SectopRAT payload (Source - Fortinet)
The SectopRAT payload (Source – Fortinet)

This investigation documents another concealment method, but does not establish a connection to those campaigns or quantify wider infections.

Fortinet Uncovers SectopRAT Variant

The attackers changed a legitimate supporting library so it would import an additional malicious component when the application’s reporting executable started.

Windows Task Scheduler launched that executable automatically, giving the modified software a way to activate without repeated user interaction.

Investigators found the altered application folder outside its normal installation location. Crucially, Fortinet found no evidence that the developer distributed compromised software.

The available evidence points to tampering with legitimate files, not a confirmed breach of the vendor’s software supply chain. The first malicious component decrypted assembly code hidden in a database file.

Comparison of the IATs of the legitimate and tampered ‘FrameworkBase.dll’ files (Source – Fortinet)

It then passed that code through another library and abused a Windows callback function, which normally processes system information, to execute the decrypted instructions instead.

That intermediate code resolved 187 Windows functions dynamically, concealing their names until execution. It decrypted the final malware from a second database file, prepared the .NET runtime, and started the 64-bit SectopRAT payload directly in memory.

Comparable in-memory malware loading techniques have appeared in other investigations, including Sauron Loader. Here, encryption, indirect calls, and multiple loading stages made the working payload less obvious than a standalone malicious executable sitting openly in an application folder.

The payload also replaced readable code names with random ones and complicated its execution flow. These changes layered additional obstacles over a loader already designed to conceal the final program during normal inspection.

Frequent calls through method pointers further hindered reverse engineering, making it harder for analysts to follow the malware’s logic and identify its functions.

Remote control

Once active, SectopRAT decrypted its controller’s address from embedded resources and attempted a connection. If that failed, it contacted one of 12 backup endpoints to recover an alternative address through several decoding and decryption steps.

Fortinet noted that these endpoints appeared related to Binance Coin infrastructure, but could not establish whether attackers had compromised them. Their use as fallback channels should not be confused with proof that their operators participated in the intrusion.

All traffic between the malware and its controller was AES-encrypted. Researchers identified 29 commands supporting screen capture, remote shell access, file and process management, computer restarts, and other administrative actions that effectively placed the device under outside control.

One command downloaded an additional browser extraction module. The malware collected saved passwords, associated website addresses, autofill records, payment-card information, and cookies. Similar browser credential theft campaigns show why a single infected device can expose several valuable accounts at once.

The targets extended beyond browsers to Thunderbird, gaming applications, wallet extensions, and desktop cryptocurrency wallets. Collected information was packaged as structured data, encrypted, and sent to the controller. An uninstall command could delete the running executable after a six-second delay.

Fortinet recommends security-awareness training to help users recognize phishing and other suspicious content, alongside seeking incident-response assistance when compromise is suspected.

Its published indicators provide investigation leads, but legitimate filenames and shared infrastructure require context rather than automatic assumptions of malicious ownership.

Indicators of compromise (IoCs):-

Type Indicator Description
C2 IP and port 98.142.252[.]140:15847 Hardcoded command-and-control server and TCP port.
Backup endpoint hxxps://bsc-dataseed1.binance[.]org/ Fallback endpoint used to recover a controller address; compromise not established.
Backup endpoint hxxps://bsc-dataseed2.binance[.]org/ Fallback endpoint used to recover a controller address; compromise not established.
Backup endpoint hxxps://bsc-dataseed3.binance[.]org/ Fallback endpoint used to recover a controller address; compromise not established.
Backup endpoint hxxps://bsc-dataseed4.binance[.]org/ Fallback endpoint used to recover a controller address; compromise not established.
Backup endpoint hxxps://bsc-dataseed1.defibit[.]io/ Fallback endpoint used to recover a controller address; compromise not established.
Backup endpoint hxxps://bsc-dataseed2.defibit[.]io/ Fallback endpoint used to recover a controller address; compromise not established.
Backup endpoint hxxps://bsc-dataseed3.defibit[.]io/ Fallback endpoint used to recover a controller address; compromise not established.
Backup endpoint hxxps://bsc-dataseed4.defibit[.]io/ Fallback endpoint used to recover a controller address; compromise not established.
Backup endpoint hxxps://bsc-dataseed1.ninicoin[.]io/ Fallback endpoint used to recover a controller address; compromise not established.
Backup endpoint hxxps://bsc-dataseed2.ninicoin[.]io/ Fallback endpoint used to recover a controller address; compromise not established.
Backup endpoint hxxps://bsc-dataseed3.ninicoin[.]io/ Fallback endpoint used to recover a controller address; compromise not established.
Backup endpoint hxxps://bsc-dataseed4.ninicoin[.]io/ Fallback endpoint used to recover a controller address; compromise not established.
Download URL hxxp://98.142.252[.]140:9000/wmglb Location serving the additional browser extraction module.
SHA-256 48D3ECBB9E0B6BABE6E53E2082A076BAD07EF61CCD98DCC8B9E4F390B937788B Tampered FrameworkBase.dll sample.
SHA-256 37FCBCB21D16866784050682C58424C91D3A736F6FD599271FA6E53CF5CA8A92 Malicious sdkcra.dll sample.
SHA-256 EFA07701570983909EF923EA79BB032F19FD9DAC0B819FA0E4F6B1161A4CC221 Activation.Desktop.db containing encrypted assembly code.
SHA-256 95F6ABD3C43EF4B33CD61D054527233DD2CE705804D44A04BE96CFB73BB52E3A pool.db containing the encrypted SectopRAT payload.
File name ReportDump.exe Legitimate reporting component launched through a scheduled task; name alone does not establish compromise.
File name FrameworkBase.dll Legitimate library modified to import the malicious loader.
File name sdkcra.dll Malicious entry library that begins payload extraction.
File name Activation.Desktop.db Database file holding encrypted intermediate code.
File name pool.db Database file holding the encrypted final payload.
File name WbElevation.dll Downloaded module assisting browser data extraction.
File name SDL3.dll Library whose exported file-reading function is used during loading; contextual artifact.
File name stp_aim_x64_vc15.dll Library used to invoke the Windows callback that executes decrypted code; contextual artifact.
File name mscoreei.dll .NET runtime component loaded before payload execution; legitimate contextual artifact.
File name clr.dll .NET runtime component loaded before payload execution; legitimate contextual artifact.
File name cmd.exe Legitimate Windows command interpreter used by the uninstall routine.
Directory C:ProgramData Location containing the tampered application folder, outside the software’s normal installation directory.

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

The post Fortinet Uncovers SectopRAT Variant Hidden Inside Tampered Legitimate Windows Software appeared first on Cyber Security News.