Malvertising Campaign Distributes SectopRAT via Fake Claude Desktop App

Malvertising Campaign Distributes SectopRAT via Fake Claude Desktop App

First seen 23 Jul 2026, 14:24 UTC HuntressFeeds2.FeedburnerFeeds.4SysopsBleepingcomputerwww.huntress.com 81% similarity 68.2

Article Content

Browse articles
ThreatCluster

A malvertising campaign, dubbed FakeAgent, exploited Bing ads to distribute the SectopRAT malware through a fake Claude desktop app. Between July 21 and July 22, 2026, at least 29 organizations were compromised after users were misled to a malicious public Claude Artifact on the legitimate Claude.ai domain. The attackers used this artifact to redirect victims to a spoofed download site, where they unknowingly downloaded a malicious executable named ClaudeDesktop.exe. This executable, disguised as a legitimate app, sideloaded a malicious DLL to deliver SectopRAT, an information-stealing Trojan. The campaign leveraged anti-analysis techniques and utilized Ethereum blockchain transactions for command-and-control operations. The malicious artifact received over 7,100 page views before being removed by Anthropic. Huntress researchers played a crucial role in analyzing the attack and attributing it to SectopRAT operations.

Key Points: • FakeAgent campaign exploited Bing ads to distribute SectopRAT malware. • 29 organizations were compromised through a malicious Claude Artifact on Claude.ai. • The malware uses advanced anti-analysis techniques and Ethereum for C2 operations.

ThreatCluster AI

Timeline

2026-07-21
FakeAgent campaign began
Malicious activity started targeting users searching for the Claude desktop app, leading to malware distribution.
Huntress
2026-07-22
29 organizations compromised
Huntress reported unusual executable installs and Defender exclusions across multiple organizations.
Huntress
2026-07-22
Malicious artifact removed
Anthropic took down the malicious Claude Artifact after it was reported, which had over 7,100 views.
Huntress
2026-07-23
Details of SectopRAT revealed
BleepingComputer reported on the malware's capabilities and the methods used for its distribution.
Bleepingcomputer

Community

Browse all →