A SectopRAT variant has been found hidden inside tampered Windows software, allowing attackers to control an infected computer and steal sensitive information.
The intrusion used legitimate application components as cover, with encrypted files concealing the malware until it was loaded into memory.
The affected program came from an Italian developer known for a long-running digital audio workstation. Attackers modified its supporting files and arranged automatic execution through a scheduled task.
The investigation did not establish how the altered software first reached the victim’s computer. Researchers from Fortinet’s FortiGuard Incident Response team identified the variant while investigating a compromised device.
Fortinet said in a report shared with Cyber Security News (CSN) that the malware combined a staged loader with extensive remote-control and information-stealing capabilities.
Also known as ArechClient2, SectopRAT is an existing malware family rather than a newly discovered threat. Earlier malicious search advertising campaigns have delivered it through deceptive downloads.
This investigation documents another concealment method, but does not establish a connection to those campaigns or quantify wider infections.
Fortinet Uncovers SectopRAT Variant
The attackers changed a legitimate supporting library so it would import an additional malicious component when the application’s reporting executable started.
Windows Task Scheduler launched that executable automatically, giving the modified software a way to activate without repeated user interaction.
Investigators found the altered application folder outside its normal installation location. Crucially, Fortinet found no evidence that the developer distributed compromised software.
The available evidence points to tampering with legitimate files, not a confirmed breach of the vendor’s software supply chain. The first malicious component decrypted assembly code hidden in a database file.
.webp)
It then passed that code through another library and abused a Windows callback function, which normally processes system information, to execute the decrypted instructions instead.
That intermediate code resolved 187 Windows functions dynamically, concealing their names until execution. It decrypted the final malware from a second database file, prepared the .NET runtime, and started the 64-bit SectopRAT payload directly in memory.
Comparable in-memory malware loading techniques have appeared in other investigations, including Sauron Loader. Here, encryption, indirect calls, and multiple loading stages made the working payload less obvious than a standalone malicious executable sitting openly in an application folder.
The payload also replaced readable code names with random ones and complicated its execution flow. These changes layered additional obstacles over a loader already designed to conceal the final program during normal inspection.
Frequent calls through method pointers further hindered reverse engineering, making it harder for analysts to follow the malware’s logic and identify its functions.
Remote control
Once active, SectopRAT decrypted its controller’s address from embedded resources and attempted a connection. If that failed, it contacted one of 12 backup endpoints to recover an alternative address through several decoding and decryption steps.
Fortinet noted that these endpoints appeared related to Binance Coin infrastructure, but could not establish whether attackers had compromised them. Their use as fallback channels should not be confused with proof that their operators participated in the intrusion.
All traffic between the malware and its controller was AES-encrypted. Researchers identified 29 commands supporting screen capture, remote shell access, file and process management, computer restarts, and other administrative actions that effectively placed the device under outside control.
One command downloaded an additional browser extraction module. The malware collected saved passwords, associated website addresses, autofill records, payment-card information, and cookies. Similar browser credential theft campaigns show why a single infected device can expose several valuable accounts at once.
The targets extended beyond browsers to Thunderbird, gaming applications, wallet extensions, and desktop cryptocurrency wallets. Collected information was packaged as structured data, encrypted, and sent to the controller. An uninstall command could delete the running executable after a six-second delay.
Fortinet recommends security-awareness training to help users recognize phishing and other suspicious content, alongside seeking incident-response assistance when compromise is suspected.
Its published indicators provide investigation leads, but legitimate filenames and shared infrastructure require context rather than automatic assumptions of malicious ownership.
Indicators of compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| C2 IP and port | 98.142.252[.]140:15847 | Hardcoded command-and-control server and TCP port. |
| Backup endpoint | hxxps://bsc-dataseed1.binance[.]org/ | Fallback endpoint used to recover a controller address; compromise not established. |
| Backup endpoint | hxxps://bsc-dataseed2.binance[.]org/ | Fallback endpoint used to recover a controller address; compromise not established. |
| Backup endpoint | hxxps://bsc-dataseed3.binance[.]org/ | Fallback endpoint used to recover a controller address; compromise not established. |
| Backup endpoint | hxxps://bsc-dataseed4.binance[.]org/ | Fallback endpoint used to recover a controller address; compromise not established. |
| Backup endpoint | hxxps://bsc-dataseed1.defibit[.]io/ | Fallback endpoint used to recover a controller address; compromise not established. |
| Backup endpoint | hxxps://bsc-dataseed2.defibit[.]io/ | Fallback endpoint used to recover a controller address; compromise not established. |
| Backup endpoint | hxxps://bsc-dataseed3.defibit[.]io/ | Fallback endpoint used to recover a controller address; compromise not established. |
| Backup endpoint | hxxps://bsc-dataseed4.defibit[.]io/ | Fallback endpoint used to recover a controller address; compromise not established. |
| Backup endpoint | hxxps://bsc-dataseed1.ninicoin[.]io/ | Fallback endpoint used to recover a controller address; compromise not established. |
| Backup endpoint | hxxps://bsc-dataseed2.ninicoin[.]io/ | Fallback endpoint used to recover a controller address; compromise not established. |
| Backup endpoint | hxxps://bsc-dataseed3.ninicoin[.]io/ | Fallback endpoint used to recover a controller address; compromise not established. |
| Backup endpoint | hxxps://bsc-dataseed4.ninicoin[.]io/ | Fallback endpoint used to recover a controller address; compromise not established. |
| Download URL | hxxp://98.142.252[.]140:9000/wmglb | Location serving the additional browser extraction module. |
| SHA-256 | 48D3ECBB9E0B6BABE6E53E2082A076BAD07EF61CCD98DCC8B9E4F390B937788B | Tampered FrameworkBase.dll sample. |
| SHA-256 | 37FCBCB21D16866784050682C58424C91D3A736F6FD599271FA6E53CF5CA8A92 | Malicious sdkcra.dll sample. |
| SHA-256 | EFA07701570983909EF923EA79BB032F19FD9DAC0B819FA0E4F6B1161A4CC221 | Activation.Desktop.db containing encrypted assembly code. |
| SHA-256 | 95F6ABD3C43EF4B33CD61D054527233DD2CE705804D44A04BE96CFB73BB52E3A | pool.db containing the encrypted SectopRAT payload. |
| File name | ReportDump.exe | Legitimate reporting component launched through a scheduled task; name alone does not establish compromise. |
| File name | FrameworkBase.dll | Legitimate library modified to import the malicious loader. |
| File name | sdkcra.dll | Malicious entry library that begins payload extraction. |
| File name | Activation.Desktop.db | Database file holding encrypted intermediate code. |
| File name | pool.db | Database file holding the encrypted final payload. |
| File name | WbElevation.dll | Downloaded module assisting browser data extraction. |
| File name | SDL3.dll | Library whose exported file-reading function is used during loading; contextual artifact. |
| File name | stp_aim_x64_vc15.dll | Library used to invoke the Windows callback that executes decrypted code; contextual artifact. |
| File name | mscoreei.dll | .NET runtime component loaded before payload execution; legitimate contextual artifact. |
| File name | clr.dll | .NET runtime component loaded before payload execution; legitimate contextual artifact. |
| File name | cmd.exe | Legitimate Windows command interpreter used by the uninstall routine. |
| Directory | C:ProgramData | Location containing the tampered application folder, outside the software’s normal installation directory. |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

