Fortinet Details SectopRAT Hidden in Legitimate Windows Software

Summary
Fortinet analyzed a SectopRAT infection in which a tampered software folder loaded the RAT from encrypted files. The malware can remotely control Windows devices and steal credentials, cookies, and wallet data.
Key points
- The investigation found a SectopRAT variant in a folder under C:\ProgramData; Fortinet found no evidence the software vendor distributed a compromised version.
- A scheduled task launched a legitimate reporting executable whose tampered FrameworkBase.dll loaded the malicious sdkcra.dll.
- The loader decrypted and executed the SectopRAT payload in memory after extracting it from encrypted data in pool.db.
- The RAT communicates with a C2 server over AES-encrypted packets and supports 29 commands, including remote shell, screen capture, and file and process management.
- It can steal browser credentials, cookies, autofill and payment data, email and gaming credentials, and cryptocurrency wallet information.
- Fortinet lists the C2 address, related URLs, sample hashes, and antivirus signatures; it says its Web Filtering and Antivirus services detect associated campaign artifacts.
Article Details
- Attack Vectors
- A scheduled task launched the legitimate ReportDump.exe from a malicious folder under C:\ProgramData. Its tampered FrameworkBase.dll imported sdkcra.dll, initiating the malware loader. The analysis found no evidence that the software vendor distributed a compromised version.
- The loader decrypted code from Activation.Desktop.db and executed it through an EnumSystemCodePagesW callback. That code decrypted the SectopRAT payload from pool.db and ran it in memory.
- SectopRAT connected to a hardcoded C2 IP address and could query 12 backup URLs for a fallback C2 address. Its C2 traffic was AES-encrypted.
- A C2 command triggered collection of browser, email-client, gaming-application, and cryptocurrency-wallet data. The malware downloaded WbElevation.dll to assist with browser-data extraction and sent collected data to its C2 server.
- Defensive Notes
- Fortinet reports that FortiGuard Web Filtering rates the associated URLs as Malicious Websites.
- Fortinet reports FortiGuard AntiVirus detections for the associated DLL and DB files and the SectopRAT payload: W64/SectopRAT.EDF4!tr, W64/SectopRAT.0846!tr, W64/SectopRAT.FD6A!tr, and W64/ShellcodeRunner.BTO!tr.
- Fortinet states that FortiGate, FortiMail, FortiClient, and FortiEDR include the FortiGuard AntiVirus engine.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| IPV4 | 98[.]142[.]252[.]140 | Hardcoded SectopRAT C2 server IP address; the reported C2 TCP port is 15847. |
| SHA256 | 37fcbcb21d16866784050682c58424c91d3a736f6fd599271fa6e53cf5ca8a92 | SHA-256 of the malicious sdkcra.dll loader. |
| SHA256 | 48d3ecbb9e0b6babe6e53e2082a076bad07ef61ccd98dcc8b9e4f390b937788b | SHA-256 of the tampered FrameworkBase.dll sample. |
| SHA256 | 95f6abd3c43ef4b33cd61d054527233dd2ce705804d44a04be96cfb73bb52e3a | SHA-256 of the pool.db file containing the encrypted SectopRAT payload. |
| SHA256 | efa07701570983909ef923ea79bb032f19fd9dac0b819fa0e4f6b1161a4cc221 | SHA-256 of the Activation.Desktop.db file containing encrypted loader code. |
| URL | hxxp[:]//98[.]142[.]252[.]140:9000/wmglb | URL from which SectopRAT downloads the WbElevation.dll module. |
| URL | hxxps[:]//bsc-dataseed1[.]binance[.]org/ | Listed backup URL queried for a fallback C2 IP address; compromise of the domain is unconfirmed. |
| URL | hxxps[:]//bsc-dataseed1[.]defibit[.]io/ | Listed backup URL queried for a fallback C2 IP address; compromise of the domain is unconfirmed. |
| URL | hxxps[:]//bsc-dataseed1[.]ninicoin[.]io/ | Listed backup URL queried for a fallback C2 IP address; compromise of the domain is unconfirmed. |
| URL | hxxps[:]//bsc-dataseed2[.]binance[.]org/ | Listed backup URL queried for a fallback C2 IP address; compromise of the domain is unconfirmed. |
| URL | hxxps[:]//bsc-dataseed2[.]defibit[.]io/ | Listed backup URL queried for a fallback C2 IP address; compromise of the domain is unconfirmed. |
| URL | hxxps[:]//bsc-dataseed2[.]ninicoin[.]io/ | Listed backup URL queried for a fallback C2 IP address; compromise of the domain is unconfirmed. |
| URL | hxxps[:]//bsc-dataseed3[.]binance[.]org/ | Listed backup URL queried for a fallback C2 IP address; compromise of the domain is unconfirmed. |
| URL | hxxps[:]//bsc-dataseed3[.]defibit[.]io/ | Listed backup URL queried for a fallback C2 IP address; compromise of the domain is unconfirmed. |
| URL | hxxps[:]//bsc-dataseed3[.]ninicoin[.]io/ | Listed backup URL queried for a fallback C2 IP address; compromise of the domain is unconfirmed. |
| URL | hxxps[:]//bsc-dataseed4[.]binance[.]org/ | Listed backup URL queried for a fallback C2 IP address; compromise of the domain is unconfirmed. |
| URL | hxxps[:]//bsc-dataseed4[.]defibit[.]io/ | Listed backup URL queried for a fallback C2 IP address; compromise of the domain is unconfirmed. |
| URL | hxxps[:]//bsc-dataseed4[.]ninicoin[.]io/ | Listed backup URL queried for a fallback C2 IP address; compromise of the domain is unconfirmed. |
MITRE ATT&CK
T1005 · Data from Local SystemSectopRAT collected sensitive data from applications and cryptocurrency wallets on the compromised device.T1008 · Fallback ChannelsIf its hardcoded C2 server was unavailable, SectopRAT queried backup URLs for an alternative C2 IP address.T1027 · Obfuscated Files or InformationSectopRAT used obfuscated .NET code, while its loader concealed encrypted code and payload data in DB files.T1053.005 · Scheduled TaskA scheduled task caused Windows Task Scheduler to launch ReportDump.exe automatically.T1059.003 · Windows Command ShellThe UnInstall command ran cmd.exe to delay and then delete SectopRAT's executable.T1070.004 · File DeletionSectopRAT's UnInstall command deleted the executable file in which it was running.T1071.001 · Web ProtocolsSectopRAT used HTTP POST requests to backup domains to obtain a C2 IP address.T1105 · Ingress Tool TransferSectopRAT downloaded the WbElevation.dll module from its C2 IP address to assist with browser-data extraction.T1113 · Screen CaptureSectopRAT supported screen capture through its C2 control commands.T1140 · Deobfuscate/Decode Files or InformationThe loader decrypted code from Activation.Desktop.db and the SectopRAT payload from pool.db at runtime.T1555.003 · Credentials from Web BrowsersSectopRAT collected saved browser credentials, associated URLs, autofill data, credit-card information, and cookies.T1573 · Encrypted ChannelSectopRAT AES-encrypted packets exchanged with its C2 server.
People
Malware
ArechClient2SectopRAT (also known as ArechClient2) is a .NET-based remote access trojan (RAT) that provides a range of functions through multiple control commands.SectopRATThe FortiGuard Incident Response (FGIR) team recently investigated an intrusion involving SectopRAT, which was used to control the victim’s device.
Vendors
Products
FortiClientFortinet FortiGate, FortiMail, FortiClient, and FortiEDR support the FortiGuard AntiVirus service, and each solution includes the FortiGuard AntiVirus engine.FortiEDRFortinet FortiGate, FortiMail, FortiClient, and FortiEDR support the FortiGuard AntiVirus service, and each solution includes the FortiGuard AntiVirus engine.FortiGateFortinet FortiGate, FortiMail, FortiClient, and FortiEDR support the FortiGuard AntiVirus service, and each solution includes the FortiGuard AntiVirus engine.FortiGuard AntivirusFortiGuard Antivirus service detects the associated DLL files and DB files, as well as the fileless SectopRAT payload file, with the following AV signatures.FortiGuard Web FilteringThe URLs associated with this campaign are rated as Malicious Websites by the FortiGuard Web Filtering service.FortiMailFortinet FortiGate, FortiMail, FortiClient, and FortiEDR support the FortiGuard AntiVirus service, and each solution includes the FortiGuard AntiVirus engine.FortiPhish Phishing Simulation ServiceThe FortiPhish Phishing Simulation Service, together with Fortinet’s Security Awareness and Training Service, uses real-world phishing scenarios to train and test employees against common social engineering tactics.Microsoft WindowsAffected Platforms: Microsoft WindowsSecurity Awareness and Training ServiceThe FortiPhish Phishing Simulation Service, together with Fortinet’s Security Awareness and Training Service, uses real-world phishing scenarios to train and test employees against common social engineering tactics.