Feeds.4Sysops Malvertising Campaign Distributes SectopRAT via Fake Claude Desktop App
Article Content
- •FakeAgent campaign exploited Bing ads to distribute SectopRAT malware.
- •29 organizations were compromised through a malicious Claude Artifact on Claude.ai.
- •The malware uses advanced anti-analysis techniques and Ethereum for C2 operations.
A malvertising campaign, dubbed FakeAgent, exploited Bing ads to distribute the SectopRAT malware through a fake Claude desktop app. Between July 21 and July 22, 2026, at least 29 organizations were compromised after users were misled to a malicious public Claude Artifact on the legitimate Claude.ai domain. The attackers used this artifact to redirect victims to a spoofed download site, where they unknowingly downloaded a malicious executable named ClaudeDesktop.exe. This executable, disguised as a legitimate app, sideloaded a malicious DLL to deliver SectopRAT, an information-stealing Trojan. The campaign leveraged anti-analysis techniques and utilized Ethereum blockchain transactions for command-and-control operations. The malicious artifact received over 7,100 page views before being removed by Anthropic. Huntress researchers played a crucial role in analyzing the attack and attributing it to SectopRAT operations.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (7)
Following this threat?
Track ClickFix and Ethereum in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Rapid7 Reports Surge in Vulnerability Exploitation Outpacing Patching Efforts Rapid7's Q2 2026 Threat Landscape Report reveals a significant increase in vulnerability disclosures, with high and critical vulnerabilities doubling to 8,539. Newly exploited vulnerabilities surged by 40%, with 62% requiring no user interaction to exploit. The report highlights that attackers are leveraging…
Healthcare Cyberattacks Disrupt Patient Care and Expose Sensitive Data Two major healthcare companies, Boston Scientific and Nutex Health, reported cyberattacks that compromised patient data and disrupted operations. Boston Scientific's systems were breached on August 25, affecting the functionality of pacemakers and other heart devices, preventing remote monitoring. The company is…