SectopRAT Returns, Hiding Inside a Legitimate Application

Toy rat on a laptop keyboard
Source: maljalen via Getty Images

Researchers discovered a variant of the SectopRAT post-compromise backdoor and infostealer hidden inside legitimate software from an Italian digital-audio company.

The operators appear to have added the remote access Trojan (RAT) after the legitimate application was installed on customer systems rather than by compromising the software vendor itself, Fortinet said in a report this week based on its analysis of the threat. The campaign shows how attackers can exploit the trust that organizations place in widely used applications to gain a foothold in their environments, while sidestepping security scrutiny in the process.

FortiGuard Labs researcher Xiaopeng Zhang, who authored the report, tells Dark Reading there's no evidence the threat actor behind the new SectopRAT campaign specifically targeted the Italian company's software, nor evidence that the adversary exploited a vulnerability in it to hide the malware.

"We believe they used the legitimate application to make the malware look less suspicious. They tampered with the FrameworkBase.dll file to secretly load the SectopRAT payload. SectopRAT has a history of disguising itself as legitimate software, such as the Notion installer and Claude Desktop," Zhang says, pointing to previous campaigns involving the malware.

A Pernicious RAT

SectopRAT, also known as ArechClient2, is a heavily obfuscated .NET-based malware that combines remote-control capabilities with extensive information-stealing functionality, including the theft of browser credentials, cookies, files, and other sensitive data. The RAT first surfaced in early 2019 and has arrived on victim systems via malicious advertising, search engine optimization (SEO) poisoning, ClickFix scams, and fake installers.

For example, in 2025, Elastic Security Labs documented a campaign in which a threat actor used the Ghostpulse malware loader to deliver SectopRAT following a ClickFix social-engineering attack. Elastic reported observing a significant increase in SectopRAT activity during 2025. In 2024, AhnLab reported seeing a threat actor distribute SectopRAT through a fake Notion installer, and more recently Bridewell said it observed an attacker delivering SectopRAT through a Trojanized version of the EarthTime application.

The variant that Fortinet discovered hidden inside a tampered copy of the audio application is another example of a threat actor using legitimate software to hide the malware. The RAT itself, according to Fortinet, was encrypted and embedded in a database file. A legitimate-looking executable and DLL-loading mechanism helped launch the malicious code.

After gaining a foothold, the malware connects to attacker-controlled infrastructure using encrypted traffic and gives the operator multiple ways to interact with the infected system, according to the security vendor. Fortinet identified 29 separate actions that the malware can execute, including manipulating files and processes, viewing the victim's screen, running commands, restarting the machine, and later, deleting malicious components to conceal signs of its activity.

SectopRAT can also function as a data-collection tool and can search browsers and other applications for credentials, cookies, saved payment information, and other account data, such as information associated with email clients, gaming services, and cryptocurrency wallets, according to Fortinet.

The main difference — besides the delivery mechanism — between the version that Fortinet analyzed and prior variants is in the network traffic, Zhang says. "The previous variant we looked at started with unencrypted traffic and then switched to encryption after the negotiation. With this new variant, the traffic is encrypted using the AES algorithm."

Why Monitoring App Behavior is Important

The latest SectopRAT campaign highlights why organizations need to pay attention to how an application behaves rather than just trusting it implicitly because it is legitimate, according to Robert Coles, senior manager of threat intelligence at Black Duck. "The takeaway isn't the malware; it's the delivery method," Coles says. Users are trained to avoid suspicious files but are far more likely to trust legitimate software.

"Security teams should focus less on whether an application looks trustworthy and more on whether its behavior is consistent with what that application should actually be doing," he says.

In addition, it's not just how well malware may be hidden, but what privileges are available to it upon arrival, says Len Noe, solutions architect at BeyondTrust. "Hiding malware inside trusted software works because trust granted by reputation is trust an attacker can borrow," he points out. "The software on your endpoints must earn trust through what it does and what it is allowed to reach, not through a name your tools recognize."

Dive deeper

Free tools to verify and analyze what this article covers:

source: DarkReading