$ techbeacon▋
Threats

Malicious RAT Disguised as Audio Software Hijacks Windows Browsers, Security Firm Says

Malicious RAT Disguised as Audio Software Hijacks Windows Browsers, Security Firm Says

A new variant of the SectopRAT remote access trojan has been uncovered masquerading as legitimate audio program files, a security analysis by FortiGuard revealed. The malware embeds itself within modified installers for popular audio editing tools, then activates a staged loading routine that extracts browser data and grants attackers remote control of the compromised Windows machines.

FortiGuard researchers say the trojan leverages the trust users place in well‑known audio software to bypass initial security checks. By inserting malicious code into the installation package, the threat actor ensures the payload is delivered alongside the expected application, making detection by conventional antivirus solutions more difficult.

Once the compromised audio program is launched, the hidden component remains dormant until a second stage is triggered. At that point, SectopRAT initiates a series of background processes that target web browsers, harvesting stored passwords, cookies, and session tokens. The stolen credentials are then transmitted to command‑and‑control servers, enabling attackers to hijack online accounts and conduct further malicious activity.

The discovery was first reported by the cybersecurity news outlet Hackread, which cited FortiGuard’s technical bulletin. According to the analysis, the malicious files retain the original software’s user interface and branding, meaning unsuspecting users are unlikely to notice any irregularities during installation or operation.

Experts note that this technique reflects a broader trend of supply‑chain abuse, where threat actors compromise legitimate software distributions to reach a wider audience. Audio and multimedia tools are attractive targets because they are frequently downloaded by both hobbyists and professionals, and they often require elevated permissions to function properly.

FortiGuard recommends users verify the authenticity of audio software downloads by checking digital signatures, using reputable sources, and keeping operating systems and security suites up to date. Organizations are also advised to monitor network traffic for unusual outbound connections that could indicate a compromised host attempting to contact remote servers.

The incident underscores the importance of vigilance in the face of increasingly sophisticated ransomware and RAT campaigns. As attackers continue to blend malicious code with trusted applications, security teams must adopt layered defenses and educate end users about the risks of downloading software from unverified channels.

Source: Hackread
Suresh Kanwar — Suresh reports on security breach post-mortems and enterprise incident response, breaking down attack timelines after major disclosures.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related