A known remote-access trojan has resurfaced in new packaging. Security researchers say attackers modified a legitimate Windows application to smuggle in SectopRAT (also tracked as ArechClient2), a mature commodity RAT built for credential theft and remote control.
What happened
Instead of dropping a standalone executable, the attackers altered one of the application's own supporting libraries so it would load an extra, malicious component the moment the program's reporting executable started. Windows Task Scheduler then launched that executable automatically, giving the malware a way to re-activate without any further action from the user.
Investigators found the tampered copy of the application sitting outside its normal installation path — evidence points to files being altered after the fact, not to the software vendor's build or distribution pipeline being compromised.
The infection chain was built to blend in. The first malicious stage decrypted its own code from data hidden inside ordinary-looking database files, passed execution through a second library, and hijacked a Windows callback function normally used for routine system reporting to run its decrypted instructions. That stage dynamically resolved more than 180 Windows functions at runtime — keeping their names out of the file on disk — before decrypting the final payload from a separate database file and launching the 64-bit SectopRAT payload directly in memory. Renamed functions, indirect calls through method pointers, and a multi-stage loading process were all layered on top, deliberately slowing down analysis.
Once running, SectopRAT decrypts a command-and-control address from its own resources and connects out; if that fails, it falls back to one of twelve backup lookup points to recover an alternate address. All communication with its controller is AES-encrypted, and researchers catalogued 29 distinct commands covering screen capture, remote shell access, file and process management, and system restarts — enough to hand an operator full remote control of an infected machine.
One of those commands pulls down a dedicated browser-extraction module that lifts saved passwords, site URLs, autofill entries, stored payment-card details, and cookies. The malware's reach extends past browsers, too — it also targets Thunderbird, gaming clients, wallet browser extensions, and desktop cryptocurrency wallets, packaging and encrypting whatever it finds before sending it out. A built-in uninstall command lets the operator delete the running executable after a short delay, cleaning up after itself.
Why it matters
SectopRAT isn't a new strain — it's a known family that has circulated for years, including via malicious search-ad campaigns. What stands out here is the packaging: hiding the loader inside a tampered copy of trusted software, triggering it through a legitimate OS scheduling mechanism, and running the final payload only in memory all raise the bar for detection tools that rely on scanning files at rest. A single successful infection can expose browser-stored passwords, saved payment cards, email data, and cryptocurrency wallets in one pass — a broad enough haul to fund follow-on fraud or account takeover well beyond the original compromise.
What to do
- Don't treat a "legitimate installer" as a trust signal on its own — verify software integrity (checksums/signatures) after install, not just at download time.
- Audit Windows Task Scheduler entries on endpoints for unfamiliar or unexplained tasks tied to application executables.
- Monitor for processes that resolve unusually large numbers of Windows API functions dynamically or execute payloads purely in memory — both are red flags for loader-style malware like this.
- Treat browser-saved passwords and payment data as a standing risk: enforce a password manager with strong master-password hygiene, and enable hardware-backed or app-based MFA wherever accounts allow it, so a stolen password alone isn't enough.
- Extend monitoring beyond browsers to email clients, gaming platforms, and both browser-extension and desktop cryptocurrency wallets, which this campaign explicitly targets.
- Run security-awareness training so users recognize the phishing and malicious-ad lures typically used to distribute this loader family, and keep an incident-response plan ready if compromise is suspected.
