A newly discovered variant of SectopRAT malware has been found concealed in tampered Windows software, enabling attackers to take over affected machines and exfiltrate sensitive information. The malware was disguised within legitimate application components, with encryption camouflaging the malicious code until it was activated in memory.
Malware Hidden in Modified Software
The compromised application originated from an Italian developer renowned for their digital audio workstation. Hackers altered the software’s supporting files, setting up automatic execution through a scheduled task. This modification allowed the malware to run without the need for user action.
During an investigation, Fortinet’s FortiGuard Incident Response team detected the variant while examining a compromised device. Although the precise method by which the altered software infiltrated the victim’s system remains unclear, the presence of the malware was confirmed. A report released by Fortinet emphasized the malware’s capabilities in remote control and data theft.
Complex Loading and Execution Techniques
Known as ArechClient2, SectopRAT is part of an existing malware family, previously distributed via malicious search advertisements. This incident showcases a new concealment method, though it does not link directly to earlier campaigns. The attackers manipulated a legitimate library to import malicious components upon the application’s execution.
The Windows Task Scheduler was used to launch the executable automatically, facilitating the malware’s activation. The investigation revealed no evidence of the developer disseminating compromised software, indicating that the tampering occurred post-distribution.
Remote Control and Data Extraction
Once activated, SectopRAT decrypted the controller’s address from internal resources and attempted connection. In case of failure, it used 12 backup endpoints to retrieve an alternative address, employing multiple decoding and decryption steps.
Fortinet identified 29 commands within the malware that allowed screen capture, remote shell access, file and process management, and more. These commands effectively placed the device under external control. Additionally, the malware deployed a browser extraction module to gather passwords, autofill data, payment information, and cookies, targeting applications beyond browsers such as cryptocurrency wallets.
Fortinet advises conducting security-awareness training to help users identify phishing attempts and other suspicious activities. They also recommend seeking incident-response support when a compromise is suspected. The published indicators of compromise provide investigative leads, but require careful context interpretation.
For more information and to enhance your security posture, consider integrating threat intelligence solutions that provide immediate context for indicators of compromise.
