Skip to content
Malvertising Campaign Distributes SectopRAT via Fake Claude Desktop App

Malvertising Campaign Distributes SectopRAT via Fake Claude Desktop App

First seen 23 Jul 2026, 14:24 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster July 24, 2026 at 11:44 UTC

A malvertising campaign, dubbed FakeAgent, exploited Bing ads to distribute the SectopRAT malware through a fake Claude desktop app. Between July 21 and July 22, 2026, at least 29 organizations were compromised after users were misled to a malicious public Claude Artifact on the legitimate Claude.ai domain. The attackers used this artifact to redirect victims to a spoofed download site, where they unknowingly downloaded a malicious executable named ClaudeDesktop.exe. This executable, disguised as a legitimate app, sideloaded a malicious DLL to deliver SectopRAT, an information-stealing Trojan. The campaign leveraged anti-analysis techniques and utilized Ethereum blockchain transactions for command-and-control operations. The malicious artifact received over 7,100 page views before being removed by Anthropic. Huntress researchers played a crucial role in analyzing the attack and attributing it to SectopRAT operations.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 48d ago How this analysis works

Timeline

2026-07-21
FakeAgent campaign began
Malicious activity started targeting users searching for the Claude desktop app, leading to malware distribution.
Huntress
2026-07-22
29 organizations compromised
Huntress reported unusual executable installs and Defender exclusions across multiple organizations.
Huntress
2026-07-22
Malicious artifact removed
Anthropic took down the malicious Claude Artifact after it was reported, which had over 7,100 views.
Huntress
2026-07-23
Details of SectopRAT revealed
BleepingComputer reported on the malware's capabilities and the methods used for its distribution.
Bleepingcomputer

More articles in this cluster (7)

Following this threat?

Track ClickFix and Ethereum in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed