Malware
SectopRAT
- First Reported
- Sep 8, 2025
- Latest Reported
- Sep 24, 2026
Reported Context (3)
- The FortiGuard Incident Response (FGIR) team recently investigated an intrusion involving SectopRAT, which was used to control the victim’s device. Fortinet Details SectopRAT Hidden in Legitimate Windows Software
- The criminals used a modified version of the CapDoor backdoor to download next-stage payloads, such as SectopRAT. CapFix Uses Evolving CapDoor Malware in Attacks on Russian Organizations
- The intrusion began when a user downloaded and executed a malicious file impersonating DeskSoft’s EarthTime application but instead dropped SectopRAT malware. DFIR Report Links Intrusion to Tools Used by Three Ransomware Groups
CVE (1)
Malware (9)
People (7)
Threat Actors (4)
MITRE ATT&CK (49)
Vendors (4)
Products (19)
Tools (8)
Industries (4)
Countries (2)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.