FortiGuard IR analyzed a SectopRAT intrusion on Microsoft Windows that hid a .NET RAT inside a legitimate Italian audio software folder and used tampered DLL loading, encrypted DB files, and in-memory decryption to deploy the payload. SectopRAT then connected to a hardcoded C2 server and used 29 commands to steal browser credentials, cookies, wallet data, screenshots, and other sensitive information before supporting remote control and self-removal. #SectopRAT #ArechClient2 #FortiGuard #MicrosoftWindows
Keypoints
- SectopRAT, also known as ArechClient2, is a .NET-based RAT used for full remote control of infected Windows systems.
- The malware payload was hidden inside a legitimate software folder and loaded through a tampered FrameworkBase.dll that imported sdkcra.dll.
- ReportDump.exe was configured as a scheduled task, allowing Windows Task Scheduler to launch the malicious chain automatically.
- The infection used encrypted DB files, custom decryption, API hashing, and indirect execution through EnumSystemCodePagesW() to run ASM code and extract the payload.
- SectopRAT used an encrypted C2 configuration, hardcoded to 98.142.252[.]140:15847, with backup domains for fallback communications.
- The RAT supports 29 control commands for screen capture, browser theft, file and process management, remote shell execution, reboot, and uninstall.
- It targets browser credentials, cookies, credit cards, wallet extensions, desktop wallets, email clients, and gaming platforms such as Steam and Battle.NET.
MITRE Techniques
- [T1027 ] Obfuscated Files or Information – The payload and supporting components were heavily concealed with obfuscation and tampering [‘heavily obfuscated’; ‘control-flow flattening’; ‘payload is hidden in a legitimate software folder’]
- [T1140 ] Deobfuscate/Decode Files or Information – The malware decrypted data from DB files into ASM code and later decrypted the final payload [‘decrypt the data into ASM code’; ‘custom decryption function’; ‘decrypt the data to recover the SectopRAT payload’]
- [T1059.003 ] Windows Command Shell – The uninstall routine executed a cmd.exe command to delete itself [‘cmd.exe /C choice /C Y /N /D Y /T 6 & Del {the full path of the current process}’]
- [T1070.004 ] File Deletion – SectopRAT removed its executable after receiving the UnInstall command [‘After the six-second delay, the malware deletes the executable file’]
- [T1555.003 ] Credentials from Web Browsers – The DeployBrowserKey command stole browser credentials, autofill data, cookies, and saved card data [‘steals credentials, associated URLs, autofill data, saved credit card information, and web browser cookies’]
- [T1113 ] Screen Capture – The RAT supported screen capture and remote-display control [‘capturing screens’; ‘Screen capture and remote-display control’]
- [T1005 ] Data from Local System – The malware collected data from local files and applications, including browsers, email clients, wallets, and gaming software [‘collecting sensitive data from the victim’s device’; ‘steals wallet data’]
- [T1573 ] Encrypted Channel – Communication with the C2 server used AES-encrypted packets [‘All packets exchanged between the C2 server and SectopRAT are AES-encrypted’]
- [T1008 ] Fallback Channels – If the main C2 was unavailable, the malware queried backup domains to recover an alternate C2 IP [‘attempts to obtain an alternative C2 IP address by sending an HTTP POST request to one of 12 backup domains’]
- [T1071.001 ] Web Protocols – The malware used HTTP POST requests to backup domains for C2 recovery [‘sending an HTTP POST request’]
Indicators of Compromise
- [IP address and port ] Hardcoded C2 server – 98.142.252[.]140:15847
- [URL ] Downloader for browser theft module – hxxp://98.142.252[.]140:9000/wmglb
- [Backup domains ] Fallback C2 domains – bsc-dataseed1.binance[.]org, bsc-dataseed2.defibit[.]io, and other 10 domains
- [File names ] Malicious and related files – FrameworkBase.dll, sdkcra.dll, Activation.Desktop.db, pool.db, and ReportDump.exe
- [SHA-256 hashes ] Relevant samples – 48D3ECBB9E0B6BABE6E53E2082A076BAD07EF61CCD98DCC8B9E4F390B937788B, 37FCBCB21D16866784050682C58424C91D3A736F6FD599271FA6E53CF5CA8A92, and other 2 hashes