SOC Prime Bias: High

01 Oct 2026 07:37 UTC

Uncovering a SectopRAT Variant Embedded in Legitimate Software

Author Photo
SOC Prime Team linkedin icon Follow
Uncovering a SectopRAT Variant Embedded in Legitimate Software
shield icon

Detection stack

  • AIDR
  • Alert
  • ETL
  • Query

Summary

Attackers are using a multi-stage loader to hide the SectopRAT remote access trojan within legitimate software. The malware relies on DLL tampering and in-memory execution of decrypted ASM code to evade security detection. Once deployed, it enables full remote control of the compromised system, credential theft, and data exfiltration.

Investigation

The FortiGuard Incident Response team discovered SectopRAT concealed inside a legitimate digital audio workstation directory under C:\ProgramData. Researchers found that FrameworkBase.dll had been modified through IAT manipulation to load a malicious sdkcra.dll. Further analysis revealed the use of API hashing and complex obfuscation techniques to conceal malware functionality and execution.

Mitigation

Organizations should ensure legitimate applications are installed only in expected directory paths rather than unusual locations such as C:\ProgramData. Robust endpoint protection should be deployed to identify DLL tampering and unauthorized scheduled task creation. Security teams should also monitor suspicious outbound connections to unknown IP addresses and backup domains impersonating cryptocurrency services.

Response

If SectopRAT activity is detected, affected Windows systems should be isolated immediately to stop further C2 communication and data exfiltration. Responders should collect memory dumps to recover the decrypted malware payload and investigate unauthorized scheduled tasks associated with ReportDump.exe. Network logs should also be reviewed for connections to 98.142.252.140 and identified Binance-themed backup domains.

Keywords: SectopRAT, remote access trojan, multi-stage loader, DLL tampering, ASM code, in-memory execution, FortiGuard Incident Response, FrameworkBase.dll, IAT modification, sdkcra.dll, API hashing, obfuscation, C:\ProgramData, ReportDump.exe, Binance, credential theft, data exfiltration, C2.

Attack Flow

We are still updating this part.

Detections

Possible Choice Usage for Delay Execution (via cmdline)

SOC Prime Team
29 Sep 2026

Possible Publicnode Ethereum Abuse Attempt As C2 Channel (via dns_query)

SOC Prime Team
29 Sep 2026

IOCs (HashSha256) to detect: Uncovering a SectopRAT Variant Embedded in Legitimate Software

SOC Prime AI Rules
29 Sep 2026

IOCs (HashMd5) to detect: Uncovering a SectopRAT Variant Embedded in Legitimate Software

SOC Prime AI Rules
29 Sep 2026

IOCs (SourceIP) to detect: Uncovering a SectopRAT Variant Embedded in Legitimate Software

SOC Prime AI Rules
29 Sep 2026

IOCs (DestinationIP) to detect: Uncovering a SectopRAT Variant Embedded in Legitimate Software

SOC Prime AI Rules
29 Sep 2026

Detect SectopRAT Variant Executing via Legitimate Software Component [Windows Process Creation]

SOC Prime AI Rules
29 Sep 2026

Simulation Execution

  • Attack Narrative & Commands: The adversary seeks to establish persistence and evade detection by using DLL Side-Loading. They drop a legitimate version of ReportDump.exe into C:ProgramData, a directory often overlooked by users but writable by certain processes. Alongside it, they place a malicious DLL named sdkcra.dll. When ReportDump.exe is executed, it searches its local directory for dependencies, loads the malicious sdkcra.dll, and executes the adversary’s payload within the context of a seemingly benign process.

  • Regression Test Script:

    # Simulation Script for SectopRAT Side-Loading Detection
    # This script creates the directory structure and files required to trigger the rule.
    
    $targetDir = "C:ProgramDataSectopSim"
    $exeName = "ReportDump.exe"
    $dllName = "sdkcra.dll"
    
    # 1. Create the directory in ProgramData
    if (!(Test-Path $targetDir)) {
        New-Item -Path $targetDir -ItemType Directory | Out-Null
    }
    
    # 2. Create a dummy 'legitimate' executable
    # In a real attack, this would be the real ReportDump.exe
    $dummyExe = [System.Text.Encoding]::ASCII.GetBytes("MZ`x00`x01`x00`x00`x00`x00`x00`x00`x00`x00")
    Set-Content -Path "$targetDir$exeName" -Value $dummyExe -NoNewline
    
    # 3. Create the malicious DLL file
    $dummyDll = [System.Text.Encoding]::ASCII.GetBytes("MZ`x00`x01`x00`x00`x00`x00`x00`x00`x00`x00")
    Set-Content -Path "$targetDir$dllName" -Value $dummyDll -NoNewline
    
    Write-Host "[+] Simulation files created in $targetDir"
    
    # 4. Trigger the detection: Execute the EXE and attempt to load the DLL
    # Note: Because these are dummy files, they won't actually 'load' as real PE files,
    # but for the sake of the detection rule logic, we simulate the file interaction.
    # In a real BAS tool, we would use a real signed binary to ensure Event ID 7 triggers.
    
    Write-Host "[*] Simulating execution of $exeName..."
    # Using a real process to simulate the behavior if the dummy files fail to trigger Event ID 7
    # To ensure the detection rule (ImageLoaded) triggers, a real DLL load is preferred.
    # For this script, we will use PowerShell to simulate the 'ImageLoaded' telemetry if possible,
    # but ideally, the user should use a real vulnerable binary.
    
    Start-Process -FilePath "$targetDir$exeName" -ErrorAction SilentlyContinue
    
    Write-Host "[!] Check your SIEM for: Image: .*\ReportDump.exe AND ImageLoaded: .*\sdkcra.dll"
  • Cleanup Commands:

    # Cleanup Script
    $targetDir = "C:ProgramDataSectopSim"
    if (Test-Path $targetDir) {
        Remove-Item -Path $targetDir -Recurse -Force
        Write-Host "[+] Cleaned up simulation files."
    } else {
        Write-Host "[-] Target directory not found. Nothing to clean."
    }