SectopRAT Malware Hidden in Audio Software
A newly discovered variant of the SectopRAT infostealer uses tampered DLL files to evade detection in audio applications.
Updated on Sept. 24, 2026 in Cybersecurity

Live Poll
Do you trust the software applications currently installed on your personal computer?
Security researchers identified a malicious variant of the .NET-based SectopRAT infostealer concealed within legitimate digital-audio software. This credential-stealing backdoor arrives via tampered DLL files, continuing a trend of embedding malware in popular productivity and creative tools.
Why it matters
By hijacking legitimate software, attackers hide malicious traffic behind trusted application processes. This tactic forces users to contend with increasingly sophisticated infostealers that now target specific industry software beyond generic installers.
The malware variant can perform 29 distinct operations, including the theft of browser cookies, credentials, and payment data. It utilizes AES-encrypted network traffic to communicate with command-and-control servers, an evolution from the simpler variants that first emerged in 2019.
The players
SectopRAT
A .NET-based post-compromise backdoor and infostealer capable of executing 29 separate malicious actions.
Fortinet
A cybersecurity firm that provides network security appliances and threat research services.
The details
The malware operates by modifying a FrameworkBase.dll file, a component responsible for loading application modules, to trigger the execution of the hidden payload upon installation. This DLL-loading mechanism allows the RAT to launch from a database file where it remains encrypted until the system is compromised. Once active, the .NET-based code enables a wide range of administrative and exfiltration tasks on the infected host machine.
Timeline
2019: SectopRAT malware first surfaced.
2024: Researchers observed SectopRAT distributed via fake Notion installer.
2025: Elastic Security Labs documented a SectopRAT campaign.
September 2026: Fortinet researchers discovered the new malware variant.
The Tech Race
This development follows a pattern of threat actors increasingly moving beyond generic installers to target niche productivity and creative software. It marks a significant shift from previous campaigns that primarily distributed malware through fake Notion and Claude Desktop installers.
Users should exercise caution when downloading audio software, particularly from unverified sources, as the malware utilizes legitimate-looking files to mask its presence. Those who suspect infection should scan for unauthorized modifications to DLL files and monitor for anomalous credential or cookie access.
The takeaway
The continued evolution of SectopRAT highlights the danger of DLL-based attacks on specialized software. Users should watch for security advisories related to audio software, which may confirm the specific applications impacted by this campaign.
Further reading
For more information on evolving threat landscapes, visit Cybersecurity.
Source note: This article includes information reported by Dark Reading.
Live Poll
Do you trust the software applications currently installed on your personal computer?






