Threat Intelligence

SectopRAT Malware Resurfaces, Hiding Inside Trusted Software

Dark Reading · 25 Sept 2026
Key Takeaway Don't rely solely on an application's reputation; monitor for unusual behaviour from installed software to catch hidden threats like SectopRAT.

Security researchers have observed a new wave of activity from SectopRAT, a remote access Trojan (RAT) that allows attackers to secretly control infected computers. In its latest form, the malware hides inside a legitimate application, making it harder for traditional security tools to spot.

By piggybacking on software that appears trustworthy, SectopRAT can slip past defences that rely on checking whether an application is known or signed correctly. Experts note that this tactic highlights a broader problem: trusting an application simply because it looks legitimate is no longer enough. Organisations need to pay closer attention to what applications actually do once they are running, not just whether they seem safe on the surface.

For small businesses, this kind of threat is a reminder that antivirus software alone may not catch malware that hides inside otherwise normal-looking programs. Monitoring unusual behaviour, such as unexpected network connections or unfamiliar processes, is an important extra layer of defence.

malware RAT SectopRAT endpoint security

Summarised by CISO AI from Dark Reading. We link back to every original so you can read it yourself.