A new Trojan, SectopRAT, has come to light, which is able to launch a hidden secondary desktop to control browser sessions on compromised machines.
The new malware was first spotted by MalwareHunterTeam. In a tweet on November 15, MalwareHunterTeam said that the C# malware, detected on November 13, was able to “create a hidden desktop and run a selected browser with full control.”
This news caught the attention of G Data security researchers, who managed to obtain a second sample, which was detected on November 14 and later submitted to Virustotal.
The first SectopRAT sample is signed by the Sectigo RSA Code Signing CA and uses a Flash, while the second is unsigned. Both Remote Access Trojan (RAT) samples use arbitrary characters in their names, have write/execute features, and make use of ConfuserEx for obfuscation.

According to the researchers, the malware contains a RemoteClient.Config class with four variables for configuration – IP, retip, filename, and mutexName.
The IP variable is related to the Trojan's command and control server (C2), while the retip variable is designed to create new C2 protocols that the server can bypass using the “set IP” command.
The filename and mutexName, however, are set but not in active use.
The hardcoded filename spoolsvc.exe is added to the registry, an imitation of Microsoft's legitimate spoolsv.exe service.
Once connected to its C2, the Trojan can either command stream an active computer session or create a secondary desktop, which is hardcoded as “sdfsddfg.” Researchers say that malware operators can use the “Init browser” command to launch a browser session via the secondary desktop.

The malware is also able to change browser parameters to disable security barriers and sandboxes. However, browser paths are hardcoded and do not use environment variables.
The malware is also able to send computer information back to the C2, such as the operating system name, processor data, basic information, and available RAM.
Another command, “Get info codec”, has not yet been implemented. The team believes that the Trojan is not yet complete, as SectopRAT “appears incomplete and with some hasty implementation steps.”.
