Feeds.4Sysops
Malvertising Campaign Distributes SectopRAT via Fake Claude Desktop App
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A malvertising campaign, dubbed FakeAgent, exploited Bing ads to distribute the SectopRAT malware through a fake Claude desktop app. Between July 21 and July 22, 2026, at least 29 organizations were compromised after users were misled to a malicious public Claude Artifact on the legitimate Claude.ai domain. The attackers used this artifact to redirect victims to a spoofed download site, where they unknowingly downloaded a malicious executable named ClaudeDesktop.exe. This executable, disguised as a legitimate app, sideloaded a malicious DLL to deliver SectopRAT, an information-stealing Trojan. The campaign leveraged anti-analysis techniques and utilized Ethereum blockchain transactions for command-and-control operations. The malicious artifact received over 7,100 page views before being removed by Anthropic. Huntress researchers played a crucial role in analyzing the attack and attributing it to SectopRAT operations.
Key Points: • FakeAgent campaign exploited Bing ads to distribute SectopRAT malware. • 29 organizations were compromised through a malicious Claude Artifact on Claude.ai. • The malware uses advanced anti-analysis techniques and Ethereum for C2 operations.