Uncovering a SectopRAT Variant Embedded in Legitimate Software
Fortinet, Thursday, September 24th, 2026
FortiGuard Labs found the SectopRAT trojan hidden inside legitimate Italian audio software using DLL tampering and multi-layer obfuscation.
FortiGuard Labs researchers uncovered a new SectopRAT campaign that conceals the .NET-based remote access trojan inside legitimate audio workstation software from an Italian vendor.
The malware tampers with FrameworkBase.dll and adds a malicious sdkcra.dll to the Import Address Table, then persists via a scheduled task.
It uses encrypted storage, hashed API resolution, and low-level ASM calls to evade detection, and supports 29 remote commands for screen capture, browser credential theft, and cryptocurrency wallet targeting. Communications are AES-encrypted across a primary C2 server and 12 backup domains.