SectopRAT returns hidden inside a legitimate music production program
Researchers at Fortinet’s FortiGuard Labs have analysed a new variant of SectopRAT, also known as ArechClient2, a remote access trojan for Windows. This time the malware was hidden inside a tampered installation of a legitimate music production program from an Italian company, placed in an unusual system folder. Fortinet clarifies that this is not a supply chain attack on the vendor but an altered copy of the program. The trick is to use a legitimate component of the software itself, set up as a scheduled task, to load a modified library that decrypts and launches the trojan.
Once active, SectopRAT lets the attacker manage the computer remotely: it captures the screen, steals browser passwords and cookies, exfiltrates files, manages processes, runs commands, restarts the system and looks for cryptocurrency wallets. Because it hides inside an application the user recognises, it easily goes unnoticed. That’s why experts insist on monitoring what applications do instead of blindly trusting them because of their name.
Tip from Soporte Informático 360
Only download software from the vendor’s official website or official stores, and be wary of “free” versions of paid software. Keep an up-to-date antivirus that analyses how applications behave and, if you notice processes or scheduled tasks you don’t recognise, have the computer checked.
Source: FortiGuard Labs (Fortinet). Summary prepared by our team for informational purposes.
Computer repair for home users
We repair desktops, laptops and mini PCs that won’t start, shut down, overheat or run slowly.