Darkreading SectopRAT Variant Discovered in Legitimate Software
Article Content
- •SectopRAT is hidden in legitimate software, allowing attackers to control compromised systems.
- •The malware was not delivered through a supply chain attack but was added post-installation.
- •Windows users are primarily affected, with a high severity level assigned to this threat.
A variant of the SectopRAT remote access trojan (RAT) has been found embedded in legitimate software from an Italian digital audio company. This multi-stage loader conceals the malware, allowing attackers to gain full remote control of affected Windows systems. The malware, identified by Fortinet's FGIR team, was not delivered through a supply chain attack but rather by tampering with the software post-installation. The SectopRAT payload is encrypted and hidden within a database file, utilizing a legitimate executable to launch it. This incident highlights the risks of trusting widely used applications without monitoring their behavior. There is currently no evidence that the software vendor distributed a compromised version of the software. The attack impacts Windows users, and the severity level is classified as high.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Following this threat?
Track Beast, Lazarus Group and ArechClient2 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Mirage Kitten Targets Aviation and FinTech with New Cross-Platform Malware The Iranian cyberespionage group Mirage Kitten has launched a campaign targeting technology professionals in the aviation and FinTech sectors across the Middle East and Africa. This operation involves the use of two newly discovered malware families, NodeRabbit and PollCat, both of which are cross-platform remote…
Iranian State Actors Deploy CHOSEN BRICK Spyware Against Dissidents On September 15, 2026, the UK, US, and Netherlands issued a joint advisory regarding a spyware campaign attributed to Iranian state actors targeting dissidents, activists, and journalists. The malware, known as CHOSEN BRICK, is delivered through spear-phishing attacks on messaging platforms like WhatsApp and Telegram.…