ThreatCluster

Fake Claude Installer Delivers SectopRAT via DLL Sideloading

First seen 26 Aug 2026, 17:36 UTC GbhackersCybersecuritynews 65

Article Content

Browse articles
ThreatCluster

A campaign using a counterfeit Claude desktop installer is targeting Windows systems, employing DLL sideloading and blockchain-based command-and-control to deploy the SectopRAT remote-access trojan. The attackers disable Windows Defender and utilize Bing malvertising to impersonate trusted software, leading to credential theft and long-term access. CyberProof researchers identified the threat through an agent-led hunt, confirming the multi-stage intrusion within ten minutes. Organizations are urged to be vigilant about trusted-looking download pages that may harbor malicious files. The full scope of the impact is still being assessed, but the campaign poses a significant risk to affected users.

Key Points: • Counterfeit Claude desktop installer used to deploy SectopRAT malware. • Attackers disable Windows Defender and exploit DLL sideloading techniques. • Campaign leverages Bing malvertising to impersonate legitimate software.

Timeline

2026-08-26
Fake Claude installer campaign identified
CyberProof researchers confirmed the use of a fake Claude desktop installer to deploy SectopRAT via DLL sideloading.
Gbhackers
2026-08-26
Malware deployment method detailed
The campaign uses blockchain-based command-and-control and Bing malvertising to impersonate trusted software.
Cybersecuritynews