Feeds.4Sysops
Malvertising Campaign Exploits Claude Artifacts to Distribute SectopRAT
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Between July 21 and July 22, 2026, a malvertising campaign targeted 29 organizations by exploiting the Claude Artifacts feature to distribute SectopRAT, a remote access trojan. Attackers used engine advertisements to redirect users to a spoofed download page on the legitimate claude.ai domain, misleading users into downloading malicious software. The campaign, dubbed FakeAgent, involved a sophisticated method of hiding command-and-control data within Ethereum blockchain transactions. The malicious artifact masqueraded as a legitimate Claude Desktop installation, leading users to download a harmful executable file. The link to the malicious artifact received over 7,100 page views before being taken down by Anthropic. This incident highlights the vulnerabilities associated with user-generated content on trusted platforms.
Key Points: • 29 organizations were targeted in a malvertising campaign using SectopRAT. • Attackers exploited the Claude Artifacts feature to distribute malware via a spoofed download page. • The malicious link received over 7,100 views before being removed by Anthropic.