Cybersecurity experts are sounding the alarm about a new variant of the remote access Trojan (RAT) known as SectopRAT, which has been discovered hiding inside a legitimate software application. The malware, also referred to as ArechClient2, combines extensive information-stealing capabilities with remote-control functions, making it a highly pernicious threat.
Researchers at Fortinet have analyzed the latest campaign and found that the attackers didn’t compromise the software vendor itself, but rather added the SectopRAT payload after the legitimate application was installed on customer systems. This tactic is particularly insidious because it exploits the trust that organizations place in widely used applications, allowing attackers to gain a foothold in their environments without raising red flags.
SectopRAT has been around since early 2019 and has been distributed through various means, including malicious advertising, search engine optimization (SEO) poisoning, ClickFix scams, and fake installers. The malware is known for its ability to disguise itself as legitimate software, such as the Notion installer or Claude Desktop. In this latest campaign, the attackers tampered with a FrameworkBase.dll file to secretly load the SectopRAT payload.
The variant analyzed by Fortinet was encrypted and embedded in a database file, with a legitimate-looking executable and DLL-loading mechanism used to launch the malicious code. Once installed, the malware connects to attacker-controlled infrastructure using encrypted traffic, giving the operator multiple ways to interact with the infected system. According to Fortinet, SectopRAT can execute 29 separate actions, including manipulating files and processes, viewing the victim’s screen, running commands, restarting the machine, and deleting malicious components.
One of the most concerning aspects of this campaign is that the malware uses a different network traffic encryption algorithm than previous variants, making it harder to detect. Fortinet researcher Xiaopeng Zhang notes that there’s no evidence the threat actor targeted the Italian company’s software specifically or exploited a vulnerability in it to hide the malware.
The latest SectopRAT campaign highlights the importance of monitoring application behavior rather than blindly trusting legitimate applications. Organizations need to be vigilant and not assume that just because an app is widely used, it’s safe from manipulation. As Zhang points out, attackers are getting increasingly sophisticated in their tactics, using legitimate software to hide malware and evade detection.
To stay ahead of threats like SectopRAT, organizations should focus on monitoring application behavior, including network traffic patterns, system calls, and other indicators of suspicious activity. This requires a combination of advanced threat detection tools and human analysis to identify potential security risks. By being more proactive in monitoring application behavior, organizations can reduce the risk of falling victim to sophisticated attacks like this one.
Source: Dark Reading — 2026-09-24