SectopRAT variant hidden in legitimate Windows software
🛡️ The FortiGuard Incident Response team investigated a Windows intrusion where a SectopRAT .NET RAT was concealed inside a legitimate audio application. The malware used a tampered DLL and a multi-stage loader that extracted an encrypted payload from a DB file, initialized the .NET runtime in memory, and executed a heavily obfuscated RAT. The variant communicates over AES-encrypted channels with a hardcoded C2 and backup domains, supports 29 control commands, and steals browser, email, gaming, and cryptocurrency wallet credentials.
