SectopRAT

31273340075?profile=RESIZE_400xSectopRAT (also known as ArechClient2) is a .NET-based remote access trojan (RAT) that provides a range of functions through multiple control commands.  These include collecting sensitive data from the victim’s device, capturing screens, remotely managing processes and files, controlling bots, and other forms of remote device management.  In the incident, Fortinet analyzed the SectopRAT payload was concealed within a legitimate program developed by an Italian company with a long-standing digital audio workstation.  Below, is an examination of the techniques used to hide and extract the SectopRAT payload, the information it can collect, and the commands its server uses to remotely control the compromised device.[1]

[1] https://hackread.com/sectoprat-abuses-audio-software-steal-pc-data/

Link to full report: IR-26-279-002_Sectoprat.pdf

E-mail me when people leave their comments –

You need to be a member of Red Sky Alliance to add comments!