Uncovering a SectopRAT Variant Embedded in Legitimate Software
Detection stack
- AIDR
- Alert
- ETL
- Query
Summary
Attackers are using a multi-stage loader to hide the SectopRAT remote access trojan within legitimate software. The malware relies on DLL tampering and in-memory execution of decrypted ASM code to evade security detection. Once deployed, it enables full remote control of the compromised system, credential theft, and data exfiltration.
Investigation
The FortiGuard Incident Response team discovered SectopRAT concealed inside a legitimate digital audio workstation directory under C:\ProgramData. Researchers found that FrameworkBase.dll had been modified through IAT manipulation to load a malicious sdkcra.dll. Further analysis revealed the use of API hashing and complex obfuscation techniques to conceal malware functionality and execution.
Mitigation
Organizations should ensure legitimate applications are installed only in expected directory paths rather than unusual locations such as C:\ProgramData. Robust endpoint protection should be deployed to identify DLL tampering and unauthorized scheduled task creation. Security teams should also monitor suspicious outbound connections to unknown IP addresses and backup domains impersonating cryptocurrency services.
Response
If SectopRAT activity is detected, affected Windows systems should be isolated immediately to stop further C2 communication and data exfiltration. Responders should collect memory dumps to recover the decrypted malware payload and investigate unauthorized scheduled tasks associated with ReportDump.exe. Network logs should also be reviewed for connections to 98.142.252.140 and identified Binance-themed backup domains.
Keywords: SectopRAT, remote access trojan, multi-stage loader, DLL tampering, ASM code, in-memory execution, FortiGuard Incident Response, FrameworkBase.dll, IAT modification, sdkcra.dll, API hashing, obfuscation, C:\ProgramData, ReportDump.exe, Binance, credential theft, data exfiltration, C2.
Attack Flow
We are still updating this part.
Detections
Possible Choice Usage for Delay Execution (via cmdline)
Possible Publicnode Ethereum Abuse Attempt As C2 Channel (via dns_query)
IOCs (HashSha256) to detect: Uncovering a SectopRAT Variant Embedded in Legitimate Software
IOCs (HashMd5) to detect: Uncovering a SectopRAT Variant Embedded in Legitimate Software
IOCs (SourceIP) to detect: Uncovering a SectopRAT Variant Embedded in Legitimate Software
IOCs (DestinationIP) to detect: Uncovering a SectopRAT Variant Embedded in Legitimate Software
Detect SectopRAT Variant Executing via Legitimate Software Component [Windows Process Creation]
Simulation Execution
-
Attack Narrative & Commands: The adversary seeks to establish persistence and evade detection by using DLL Side-Loading. They drop a legitimate version of
ReportDump.exeintoC:ProgramData, a directory often overlooked by users but writable by certain processes. Alongside it, they place a malicious DLL namedsdkcra.dll. WhenReportDump.exeis executed, it searches its local directory for dependencies, loads the malicioussdkcra.dll, and executes the adversary’s payload within the context of a seemingly benign process. -
Regression Test Script:
# Simulation Script for SectopRAT Side-Loading Detection # This script creates the directory structure and files required to trigger the rule. $targetDir = "C:ProgramDataSectopSim" $exeName = "ReportDump.exe" $dllName = "sdkcra.dll" # 1. Create the directory in ProgramData if (!(Test-Path $targetDir)) { New-Item -Path $targetDir -ItemType Directory | Out-Null } # 2. Create a dummy 'legitimate' executable # In a real attack, this would be the real ReportDump.exe $dummyExe = [System.Text.Encoding]::ASCII.GetBytes("MZ`x00`x01`x00`x00`x00`x00`x00`x00`x00`x00") Set-Content -Path "$targetDir$exeName" -Value $dummyExe -NoNewline # 3. Create the malicious DLL file $dummyDll = [System.Text.Encoding]::ASCII.GetBytes("MZ`x00`x01`x00`x00`x00`x00`x00`x00`x00`x00") Set-Content -Path "$targetDir$dllName" -Value $dummyDll -NoNewline Write-Host "[+] Simulation files created in $targetDir" # 4. Trigger the detection: Execute the EXE and attempt to load the DLL # Note: Because these are dummy files, they won't actually 'load' as real PE files, # but for the sake of the detection rule logic, we simulate the file interaction. # In a real BAS tool, we would use a real signed binary to ensure Event ID 7 triggers. Write-Host "[*] Simulating execution of $exeName..." # Using a real process to simulate the behavior if the dummy files fail to trigger Event ID 7 # To ensure the detection rule (ImageLoaded) triggers, a real DLL load is preferred. # For this script, we will use PowerShell to simulate the 'ImageLoaded' telemetry if possible, # but ideally, the user should use a real vulnerable binary. Start-Process -FilePath "$targetDir$exeName" -ErrorAction SilentlyContinue Write-Host "[!] Check your SIEM for: Image: .*\ReportDump.exe AND ImageLoaded: .*\sdkcra.dll" -
Cleanup Commands:
# Cleanup Script $targetDir = "C:ProgramDataSectopSim" if (Test-Path $targetDir) { Remove-Item -Path $targetDir -Recurse -Force Write-Host "[+] Cleaned up simulation files." } else { Write-Host "[-] Target directory not found. Nothing to clean." }