Skip to content
SectopRAT Returns, Hiding Inside a Legitimate Application

SectopRAT Returns, Hiding Inside a Legitimate Application

Darkreading • September 24, 2026

The latest activity from the remote access Trojan (RAT) shows why organizations should monitor the behavior of applications rather than blindly trusting them, experts say.

Researchers discovered a variant of the SectopRAT post-compromise backdoor and infostealer hidden inside legitimate software from an Italian digital-audio company.

The operators appear to have added the remote access Trojan (RAT) after the legitimate application was installed on customer systems rather than by compromising the software vendor itself, Fortinet said in a report this week based on its analysis of the threat. The campaign shows how attackers can exploit the trust that organizations place in widely used applications to gain a foothold in their environments, while sidestepping security scrutiny in the process.

FortiGuard Labs researcher Xiaopeng Zhang, who authored the report, tells Dark Reading there's no evidence the threat actor behind the new SectopRAT campaign specifically targeted the Italian company's software, nor evidence that the adversary exploited a vulnerability in it to hide the malware.

Related: 3 Cyber Threats That Defined the Summer of 2026

"We believe they used the legitimate application to make the malware look less suspicious. They tampered with the FrameworkBase.dll file to secretly load the SectopRAT payload. SectopRAT has a history of disguising itself as legitimate software, such as the Notion installer and Claude Desktop," Zhang says, pointing to campaigns involving the malware.

SectopRAT, also known as ArechClient2, is a heavily obfuscated .NET-based malware that combines remote-control capabilities with extensive information-stealing functionality, including the theft of browser credentials, cookies, files, and other sensitive data. The RAT first surfaced in early 2019 and has arrived on victim systems via malicious advertising, engine optimization (SEO) poisoning , ClickFix scams, and fake installers.

For example, in 2025, Elastic Security Labs documented a campaign in which a threat actor used the Ghostpulse malware loader to deliver SectopRAT following a ClickFix social-engineering attack. Elastic reported observing a significant increase in SectopRAT activity during 2025. In 2024, AhnLab reported seeing a threat actor distribute SectopRAT through a fake Notion installer, and more recently Bridewell said it observed an attacker delivering SectopRAT through a Trojanized version of the EarthTime application.

The variant that Fortinet discovered hidden inside a tampered copy of the audio application is another example of a threat actor using legitimate software to hide the malware. The RAT itself, according to Fortinet, was encrypted and embedded in a database file. A legitimate-looking executable and DLL-loading mechanism helped launch the malicious code.

Related: Ghost Service Accounts Enable M365 Data Theft in Chile

After gaining a foothold, the malware connects to attacker-controlled infrastructure using encrypted traffic and gives the operator multiple ways to interact with the infected system, according to the security vendor. Fortinet identified 29 separate actions that the malware can execute, including manipulating files and processes, viewing the victim's screen, running commands, restarting the machine, and later, deleting malicious components to conceal signs of its activity.

SectopRAT can also function as a data-collection tool and can browsers and other applications for credentials, cookies, saved payment information, and other account data, such as information associated with email clients, gaming services, and cryptocurrency wallets, according to Fortinet.

The main difference — besides the delivery mechanism — between the version that Fortinet analyzed and prior variants is in the network traffic, Zhang says. "The variant we looked at started with unencrypted traffic and then switched to encryption after the negotiation. With this new variant, the traffic is encrypted using the AES algorithm."

Why Monitoring App Behavior is Important

The latest SectopRAT campaign highlights why organizations need to pay attention to how an application behaves rather than just trusting it implicitly because it is legitimate, according to Robert Coles, senior manager of threat intelligence at Black Duck. "The takeaway isn't the malware; it's the delivery method," Coles says. Users are trained to avoid suspicious files but are far more likely to trust legitimate software .

Related: Shai-Hulud Attack Nips Cyber-Firm CrowdSec's GitHub Data

"Security teams should focus less on whether an application looks trustworthy and more on whether its behavior is consistent with what that application should actually be doing," he says.

In addition, it's not just how well malware may be hidden, but what privileges are available to it upon arrival, says Len Noe, solutions architect at BeyondTrust. "Hiding malware inside trusted software works because trust granted by reputation is trust an attacker can borrow," he points out. "The software on your endpoints must earn trust through what it does and what it is allowed to reach, not through a name your tools recognize."

Illinois-based Jai Vijayan is a veteran, award-winning technology journalist with more than 25 years of experience covering cybersecurity. His information security reporting has explored everything from ransomware, nation-state threats, and identity security to AI risk, critical infrastructure protection, software supply chain security, cloud security and emerging enterprise technologies.

Over the course of his career, Jai has written news stories, feature articles, survey reports, white papers, and e-books for enterprise and technology audiences. He has also moderated panel discussions and executive roundtables featuring CISOs, security researchers, and industry leaders.

Jai previously served as senior editor at Computerworld, where he covered information security and data-privacy issues. His work has also appeared in CSO Online, InformationWeek, The Christian Science Monitor Passcode, The Economic Times, and other publications.

His work has earned multiple industry honors, including a Joint ASBPE Excellence Award for Best Coverage of Government IT, and a Joint Jesse H. Neal Award for wireless LAN security coverage. Jai holds a Master’s degree in statistics from Bangalore University, and studied broadcasting and electronic communication at Marquette University in Milwaukee.

Want more Dark Reading stories in your Google results?

The State of Cloud Security: The Latest Challenges

The State of Cloud Security: The Latest Challenges

How Organizations Are Managing Incident Response

How Organizations Are Managing Incident Response

How Enterprises Are Developing Secure Applications

How Enterprises Are Developing Secure Applications

Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy

Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy

Essential News & Insights from Black Hat USA 2025

Essential News & Insights from Black Hat USA 2025

Effective Alert Triage: Reducing Noise and Finding Real Threats

Effective Alert Triage: Reducing Noise and Finding Real Threats

Cybersecurity Outlook 2027

Cybersecurity Outlook 2027

Threat Exposure Analytics: Measuring and Communicating Security Risk

Threat Exposure Analytics: Measuring and Communicating Security Risk

Benchmark Scores Are a False Flag

Benchmark Scores Are a False Flag

Building an Effective Red Team: Beyond Penetration Testing

Building an Effective Red Team: Beyond Penetration Testing

Operation DoppelBrand: Weaponizing Fortune 500 Brands

CISA Warns of 'Ongoing' Brickstorm Backdoor Attacks

Deja Vu: Salesforce Customers Hacked Again, Via Gainsight

Jaguar Land Rover Shows Cyberattacks Mean (Bad) Business

Extracted Entities