The remote access Trojan known as SectopRAT has returned, this time concealing itself inside a legitimate application. According to Dark Reading, the latest activity shows how attackers are abusing trusted software to slip past defenses that rely on reputation or allowlists.

Experts cited in the report argue that this approach exposes a fundamental weakness in many security strategies: treating an application as safe simply because it is known or signed. Instead, they say, organizations should focus on what applications actually do at runtime, watching for suspicious behavior even when the software appears legitimate.

The report does not suggest that all legitimate applications are dangerous, but it makes clear that attackers are increasingly willing to use them as camouflage. For defenders, the lesson is that trust must be earned continuously, not granted permanently.