Researchers from Fortinet have uncovered a variant of the SectopRAT remote-access Trojan embedded in legitimate Windows software, using stealthy tactics to evade detection. The malware was concealed inside modified components of a digital audio workstation from an Italian developer, with parts of the software altered to include malicious payloads. The investigators believe the infection was never distributed by the vendor, but rather inserted by attackers after the software was already installed on a victim’s system.
How the Infection Unfolded
The intrusion used a multi-stage loader design leveraging legitimate DLL files. A modified supporting library—\u201cFrameworkBase.dll\u201d—was altered so that when the application’s legitimate reporting executable launched, it would also load a malicious component. The attackers placed the application folder outside its expected installation path, and scheduled automatic execution via Windows Task Scheduler to start the exploit without further user action.
Initial steps involved decrypting assembly code hidden within a database file. This intermediate code was passed through another library, which exploited a Windows callback function to run decrypted instructions. These instructions dynamically resolved nearly 200 Windows API calls, hiding their identities until runtime. The final SectopRAT payload was tucked away in a separate database file and executed in memory using the .NET runtime.
Capabilities and Communication
This SectopRAT variant establishes control by reaching out to hard-coded command-and-control infrastructure. If primary servers are unreachable, it falls back to one of a dozen backup endpoints, some linked to Binance Coin infrastructure (though Fortinet saw no proof that those services themselves were compromised).
Once connected, it supports at least 29 commands enabling full remote control: taking screenshots, executing shell commands, managing files and processes, restarting machines. It also steals credentials from a wide range of sources—including browsers, autofill data, payment card information, cookies, desktop crypto wallets, gaming applications, and browser extensions. There’s even an uninstall command that triggers deletion after a short delay.
Indicators & Mitigation
Fortinet provided several indicators of compromise (IoCs): notable file hashes for modified files like \u201cFrameworkBase.dll\u201d and malicious loader DLLs; the presence of particular backup endpoint URLs; and the use of legitimate Windows paths like ProgramData for storing the tampered application folder. The reporting executable involved is named \u201cReportDump.exe\u201d, though file names alone are never definitive proof of compromise.
For protection, Fortinet urges organizations to invest in security training so users can better identify phishing and suspicious downloads. When compromise is suspected, they recommend engaging incident-response experts. The report emphasizes that while some infrastructure overlaps legitimate services, analysts must interpret IoCs in context rather than assuming malicious ownership automatically.
What this means: This discovery reinforces how adversaries are increasingly abusing trust relationships in legitimate software components and evading standard detection tools. The use of scheduled tasks, in-memory execution, encrypted artifacts, and staging make such threats substantially harder to catch. Going forward, teams should scrutinize application provenance, monitor scheduled tasks, and consider runtime behaviors—not just static files. The next battleground in cybersecurity lies in the gaps attackers exploit between legitimacy and compromise.