Fortinet researchers confirm SectopRAT attack on Windows users

The cybersecurity news cycle is nothing if not repetitive, a fact confirmed by a SectopRAT attack on Windows. According to newly published analysis from FortiGuard researcher Xiaopeng Zhang, the latest variant comes hidden within “tampered legitimate software that steals credentials and enables remote system control”.

SectopRAT first came to my attention in, wait for it, 2019, when an NHS Digital advisory warned security teams about the then new .NET-based remote access trojan being actively sold through cybercrime forums. In 2023, Darktrace observed “a resurgence of the SectopRAT across customer environments” across the education sector in the US, Europe, the Middle East and Africa, and Asia-Pacific regions.

Jump forward another couple of years, and the threat was still active. Malwarebytes security labs reported that the remote access trojan was being bundled in a fake Chrome browser installer distributed via malicious Google Ads.

Latest SectopRAT variant

Fast forward to now, and Zhang has warned that this SectopRAT variant (also known as ArechClient2) is capable of collecting sensitive data from the victim’s device, capturing screens, remotely managing processes and files, controlling bots, and other forms of remote device management.

The malware was hidden within legitimate software, described only as being by a genuine company with a long-standing digital audio workstation product. It used a multi-stage loader to extract its payload from files, applied API hashing and indirect function calls, as well as in-memory loading to execute the final .NET payload.

“We believe the attackers used the legitimate application to make the malware look less suspicious” Zhang told me. “They tampered with the FrameworkBase.dll file to secretly load the SectopRAT payload. SectopRAT has a history of disguising itself as legitimate software, such as the Notion installer and Claude Desktop.”

Beware of the delivery method

The delivery method being the key takeaway here, according to Robert Coles, Senior Manager of Threat Intelligence Security at Black Duck. “Users are trained to avoid suspicious files,” Coles said, “but they’re far more likely to trust legitimate software.”

Which means that security teams must start to focus less on whether an application looks trustworthy “and more on whether its behaviour is consistent with what that application should actually be doing”.

Jason Soroko, Senior Fellow at Sectigo, agrees. “The staged loading and in-memory execution make it important to monitor what software does after installation,” Soroko told TechFinitive, “not just scan the downloaded file.”

I mean, as Soroko sagely advised, an audio program accessing browser credentials or running unrelated commands should prompt investigation, regardless of its name.

I will leave the last word to Len Noe, Solutions Architect at BeyondTrust, who concluded: “Identity alone doesn’t create risk. Privilege does. Every credential cached in a browser, every long-lived session, and every local administrator right on a workstation is a potential path to privilege. Malware like SectopRAT is simply an efficient way to collect those paths in bulk. That’s especially true because stolen credentials outlive the infection itself.”

More from Davey

About The Author

Avatar photo
Davey Winder

With four decades of experience, Davey is one of the UK's most respected cybersecurity writers and a contributing editor to PC Pro magazine. He is also a senior contributor at Forbes. You can find him at TechFinitive covering all things cybersecurity.

Read more from this author.

We take journalism seriously. To learn more on why you should trust us, head to our editorial guidelines page or meet our team.