Bing search service malvertising campaigns push faux Claude desktop app installers hosted on reputable Claude.ai domains to ship SectopRAT malware.
The malicious operation, which researchers name “FakeAgent,” compromised a minimum of 29 organizations between July 21 and 22.
The attacker makes use of a malicious Claude artifact hosted on Claude’s reputable area. This can be a frequent tactic that has been used up to now.
The attacker used a malicious Claude Artifact hosted on Claude’s reputable area. This can be a tactic used earlier this yr to push macOS malware through the ClickFix lure.
Researchers at managed safety agency Huntress found that the malicious Claude Artifact, which was downloaded 7,100 instances earlier than being eliminated by Anthropic, was directing guests to a web site internet hosting a faux installer named: ClaudeDesktop.exe.

Supply: Huntress
Nevertheless, this file is a reputable JetBrains Chromium element that sideloads a malicious DLL (libcef.dll) Delivers the SectopRAT distant entry Trojan with the flexibility to steal data.
Persistence on the system is achieved by one other executable named . DockerDesktop.exe, This can set up the scheduled process.
In keeping with Huntress, the varied loaders and staging elements used within the an infection chain are outfitted with anti-analysis mechanisms corresponding to VMProtect packing, shader timing checks, GPU and VRAM checks, and digital machine (VM) detection.
SectopRAT malware was just lately noticed being distributed through CastleLoader campaigns and ClickFix assaults.
The malware makes use of EtherHiding expertise to acquire legitimate command and management (C2) addresses through Ethereum BNB good chain transactions.
SectopRAT, also referred to as ArechClient2, has been energetic since 2019 and is an data stealer with Hidden Digital Community Computing (HVNC) capabilities. This enables for distant hands-on operations and real-time interplay with compromised techniques.
The malware targets customers’ passwords, bank card knowledge, information, browser logins and cookies, FTP credentials, and knowledge from varied messaging purchasers corresponding to Discord, Telegram, Steam, and VPN merchandise.

Supply: Huntress
In an fascinating growth, Huntress stories that it used Claude Opus 4.8 to help with shader emulation, cryptographic reconstruction, and .NET code evaluation.
Evaluation of the decrypted .NET payload (SectopRAT) recognized the supply of the assault as a SectopRAT operation, or a intently associated fork, paving the best way for infrastructure evaluation.
At that stage, researchers found 10 domains registered to the identical e mail tackle from December 2025 onwards, one among which had beforehand been linked to the StealC distribution and seized throughout Operation Endgame.
Huntress doesn’t have adequate proof to attribute the FakeAgent marketing campaign to any particular identified menace cluster.
Customers on the lookout for software program ought to belief official web sites and obtain portals quite than search outcomes, particularly sponsored websites.
Safety groups doc 54% of profitable assaults and problem a warning on solely 14%. The remainder strikes invisibly by way of the atmosphere.
Picus’ whitepaper exhibits the way to check your SIEM and EDR guidelines in breach and assault simulations to make sure threats go undetected.
Get the white paper
