Looks legitimate. Runs legitimate. Carries a RAT. π
Our team investigated a
#SectopRAT variant concealed inside legitimate software and unpacked through a multi-stage loader before executing in memory.
Once active, it gives attackers broad remote control, including screen capture, file and process management, command execution, and access to sensitive data from browsers, email clients, gaming platforms, and crypto wallets.
π See how the payload stays hidden and what it can do:
ow.ly/QvuS50ZR8Hz