FortiGuard Incident Response identified a Windows intrusion in which attackers embedded the .NET-based SectopRAT (ArechClient2) remote-access Trojan and infostealer in tampered components of legitimate digital-audio workstation software from an unnamed Italian developer. Investigators found no evidence that the vendor distributed compromised software or that an application vulnerability was exploited; the malware appears to have been inserted after installation on customer systems.
The attackers modified FrameworkBase.dll and placed malicious files under C:\ProgramData, using a scheduled task, DLL side-loading, and in-memory execution to decrypt a payload hidden in a database file. SectopRAT communicates with a hardcoded command-and-control server or fallback domains over AES-encrypted traffic and supports 29 capabilities, including command execution, screen viewing, process and file operations, system restart, and artifact cleanup. An optional WbElevation.dll module steals browser credentials, cookies, payment-card data, application data, email-client and gaming-service information, files, and cryptocurrency-wallet data.

Pull IOCs and campaign context straight into your stack.
7 events from the most recent confirmed update back to the earliest known activity.
Elastic Security Labs reported a significant increase in SectopRAT activity.
Elastic Security Labs documented a campaign in which Ghostpulse delivered SectopRAT following a ClickFix social-engineering attack.
AhnLab reported that SectopRAT was distributed through a fake Notion installer.
SectopRAT, also known as ArechClient2, first emerged as a .NET-based remote-access trojan and information stealer.
The altered files, found under C:\ProgramData, used a scheduled task to launch ReportDump.exe and a modified FrameworkBase.dll to load malicious DLLs and decrypt the SectopRAT payload from database files for in-memory execution. The final payload used AES-encrypted C2 traffic, supported 29 commands, and could download WbElevation.dll to steal browser, application, and cryptocurrency-wallet data.
FortiGuard Incident Response investigated a Windows intrusion involving SectopRAT concealed in tampered components associated with digital-audio-workstation software from an unnamed Italian developer. Researchers found no evidence that the vendor distributed compromised software or that a vulnerability in its application was exploited.
Bridewell observed SectopRAT being delivered through a Trojanized EarthTime application.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.