At a Glance
| Attribute | Details |
|---|---|
| Malware Family | SectopRAT (also known as ArechClient2) |
| Threat Actor | Unknown (Unconfirmed attribution) |
| Target Victims | Corporate workstations and creative audio professionals |
| Delivery Vector | Locally tampered application binaries staged in ProgramData |
| Key Capabilities | Browser credential theft, crypto wallet theft, remote shell, process manipulation |
| Source | FortiGuard Incident Response (FGIR) |
Executive Summary
Fortinet researchers uncovered an attack chain deploying the SectopRAT malware on compromised Windows systems. The attackers concealed the payload inside a legitimate audio reporting tool rather than distributing clean vendor software. Once triggered, the multi-stage loader extracts an encrypted .NET backdoor that steals browser data, email logins, and cryptocurrency wallets.
Delivery and Staging Tactics
The threat actors staged the attack files inside the Windows ProgramData directory. This location does not match the vendor’s normal installation path. The folder contained a legitimate application component named ReportDump.exe. In legitimate installations, this program handles crash and error reporting tasks.
However, investigators found no evidence of a compromised vendor supply chain. Instead, the attackers modified local software libraries after gaining access to the machine. Fortinet confirmed, “The evidence indicates that the legitimate software was tampered with by modifying FrameworkBase.dll and adding the malicious sdkcra.dll as an imported module.”
Furthermore, the attackers created a Windows scheduled task for ReportDump.exe. This task instructed Task Scheduler to run the executable automatically. Consequently, the infection established persistence and loaded malicious modules without prompting the user.
Infection Chain Architecture
When ReportDump.exe launches, it automatically imports FrameworkBase.dll. The tampered import address table immediately forces the system to load sdkcra.dll. Next, this entry library executes an exported function to begin unpacking secondary stages.
The library reads encrypted data from a database file named Activation.Desktop.db. It accesses the file through legitimate multimedia programming interfaces provided by SDL3.dll. Then, the malware calls an internal decryption routine to transform this data into executable assembly code.
To execute the decrypted code, the loader abuses a standard Windows programming interface. Specifically, it calls the EnumSystemCodePagesW function. The malware assigns the decrypted code address to a callback parameter. When Windows processes installed code pages, it executes the malicious assembly code directly.
The assembly routine uses API hashing to resolve 187 hidden system functions dynamically. Next, it reads encrypted bytes from a second database file named pool.db. The routine applies a custom decryption function using a single-byte key. As a result, it extracts the final 64-bit .NET assembly payload directly into memory.
The payload code features heavy obfuscation to hinder reverse engineering. For example, it randomizes class names and flattens program control flow. In addition, the malware uses method pointers rather than standard function calls. This design prevents static scanners from inspecting internal routines.
Command-and-Control and Data Exfiltration Behavior
During startup, the SectopRAT malware variant decrypts its primary command server address and port number from internal resources. If the primary server fails to respond, the malware initiates an alternative discovery sequence. It sends web requests to twelve backup domains associated with Binance Coin mining.

The server response returns a hexadecimal string containing an encrypted address. Then, the malware extracts and decrypts the IP address to restore communication. All communications exchanged between the trojan and its controller use symmetric encryption algorithms. The client encodes stolen data into structured JSON messages before transmission.
The backdoor supports 29 distinct control commands. These commands allow operators to manage running processes, capture desktop displays, and restart the host. In addition, the malware can execute remote shell commands and delete itself upon receiving an uninstall instruction.
When the controller issues the data theft command, the trojan downloads an elevation module named WbElevation.dll. It then harvests credentials, autofill records, cookies, and credit cards from over 35 web browsers. The target list includes Google Chrome, Microsoft Edge, Mozilla Firefox, Brave, and Opera. Furthermore, the malware targets desktop email clients like Thunderbird and extracts cryptocurrency wallets, including MetaMask, Exodus, and Atomic Wallet.
Attribution Analysis
FortiGuard analysts classify the attribution for this intrusion as unconfirmed. The attackers left no distinct nation-state identifiers within the script files. However, the operational focus on cryptocurrency wallets and financial credentials points to financially motivated cybercrime actors.
Defense and Detection Guidance
Security administrators must monitor unexpected executable activity inside the ProgramData directory. System tools should inspect the import address tables of common application libraries for unauthorized module references. In addition, defenders should watch for legitimate executables spawning system shells with delayed file deletion commands.
Network teams should block known command-and-control addresses and monitor traffic for unusual API hash resolutions. Finally, endpoint detection systems should alert when programs abuse code page enumeration functions to execute unmapped memory blocks.
Support Our Threat Intelligence
Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!