Back Issues/Search Home → Calendar → Archive → RSS → Subscribe → Current Issue → Popular →

All issues › Volume 342, Issue 4 › IT Vendor News › Fortinet

Uncovering a SectopRAT Variant Embedded in Legitimate Software

Fortinet, Thursday, September 24th, 2026

FortiGuard Labs found the SectopRAT trojan hidden inside legitimate Italian audio software using DLL tampering and multi-layer obfuscation.

FortiGuard Labs researchers uncovered a new SectopRAT campaign that conceals the .NET-based remote access trojan inside legitimate audio workstation software from an Italian vendor.

The malware tampers with FrameworkBase.dll and adds a malicious sdkcra.dll to the Import Address Table, then persists via a scheduled task.

It uses encrypted storage, hashed API resolution, and low-level ASM calls to evade detection, and supports 29 remote commands for screen capture, browser credential theft, and cryptocurrency wallet targeting. Communications are AES-encrypted across a primary C2 server and 12 backup domains.

more →  ·  More from Fortinet →