DEV Community

kozhevniko
kozhevniko

Posted on

SectopRAT in Tampered Audio Software Components: A Loader That Uses the Host's Own Imports

SectopRAT in Tampered Audio Software Components: A Loader That Uses the Host's Own Imports

Remote access trojans benefit from delivery that produces no separate installer and no unfamiliar file for a user to double-click. A September 2026 investigation described one such chain, where the trojan arrived inside components of legitimate digital audio software and used the host application's own loading behaviour to start.

What the investigation found

The research described a variant of SectopRAT, also tracked as ArechClient2, delivered through tampered components of a legitimate digital audio workstation produced by an Italian company. The modified files were found in the ProgramData directory of the affected machine rather than in the software's normal installation folder, and the researchers stated explicitly that they found no evidence the vendor distributed a compromised version.
The chain is layered, which is what makes it worth studying. A scheduled task launches a component named as a crash reporter. That component loads a library whose import address table, the list defining which libraries a program loads, had been modified. The modification causes a different library to load first, and that library decrypts assembly code held inside it. The decrypted code is handed to a function exported by an SDK support library, which abuses a Windows callback mechanism to execute the decrypted content in memory.
The next stage resolves 187 Windows API functions using hashing to avoid naming them, reads encrypted data from a file named pool.db, decrypts it, and recovers the payload. The final trojan is a 64-bit managed executable that calls functions through memory addresses using calli instructions and applies control flow flattening to complicate analysis.

Why the delivery method is the interesting part

Nothing in the chain requires a user to run an installer. The components are placed in a directory that the operating system treats as application data, and the execution path is a scheduled task that looks like crash reporting. The modified file is a library inside a product the user already trusts and already runs.
For defenders, this shifts the detection question. File reputation based on the original vendor signature is not useful when the file itself has been altered, and the modification is a change to an import table rather than the addition of new code. The observable events are a scheduled task that starts a binary from a non-standard location, and a library loaded from a path that differs from the product's installation directory.

Capability and follow-on behaviour

The investigation identified 29 commands available to the operator, covering screen capture, file and process management, remote command execution, system restart and data collection. Command and control traffic is encrypted with AES and used a hardcoded endpoint, with 12 fallback domains contacted by HTTP POST when the primary was unavailable. The fallback domains appeared to be associated with cryptocurrency mining, and the researchers could not determine whether those domains had been compromised by the same actor.
A further module is downloaded on demand to collect browser credentials, saved payment card data and cookies, and additionally to search data held by mail clients, gaming platforms, graphics software and both desktop and browser-based cryptocurrency wallets. The trojan also supports a removal command that deletes its executable after a short delay, allowing a running process to release the file.

Response guidance

Search for scheduled tasks that launch binaries from application data directories rather than from program installation paths, since that is the observed execution mechanism. Treat a modified import table inside a signed product as a detection signal in its own right, and compare libraries against known-good copies rather than relying on the presence of a signature. Block outbound requests to endpoints that do not correspond to a business purpose, and log DNS resolution for the fallback pattern. Restrict the ability to create scheduled tasks to administrative roles. Where the platform allows it, enforce application control so that only libraries from expected directories load into a trusted process.
The broader lesson concerns provenance at the file level. Software obtained from an official channel remains the right starting position, and a compromise that alters files after installation defeats that control without contradicting it.

References

Top comments (1)

Collapse
 
analista_83 profile image
Sammi De Blas •

Two additions on the detection side. The import-table change is exactly what Sysmon EID 7 already captures without any baseline: an ImageLoaded whose module path differs from the host image install directory fires even while the file still carries a valid signature, so comparing against known-good copies can be upgraded to a live rule. And pool.db being read next to a scheduled task that points into ProgramData is a cheap triage pair — hunt those two together and you catch this chain before the 187 hashed API resolutions ever matter.