Bing malvertising impersonates Claude to deliver SectopRAT malware

A Bing search malvertising campaign promoted a fake Claude desktop installer hosted on Claude.ai to deliver the SectopRAT information-stealer/HVNC malware, compromising at least 29 organizations on July 21–22. The fake ClaudeDesktop.exe loader hijacks a legitimate JetBrains Chromium component to load a malicious DLL, with persistence via a DockerDesktop.exe‑spawned scheduled task and multiple anti‑analysis checks. SectopRAT, active since 2019, exfiltrates credentials and supports remote control; the campaign also leveraged Claude Opus 4.8 for analysis. Researchers found about 10 domains tied to the same email since December 2025, but there isn’t enough evidence to link FakeAgent to a known threat group. The advisory advises downloading software only from official sources and avoiding sponsored results.
- Fake Claude app promoted by Bing ads pushes SectopRAT malware BleepingComputer
- Hackers hid dangerous malware on a page hidden in Anthopic's Claude.ai domain TechRadar
- Fake Claude Desktop Ads Hit 29 Organisations With Data-Stealing Malware TechRound
- How attackers hosted a fake Claude download page on the claude.ai domain Help Net Security
- FakeAgent Campaign: Malicious Claude Artifact Used to Distribute SectopRAT to 29 Organisations IT Security Guru
Reading Insights
1
7
3 min
vs 4 min read
84%
691 → 112 words
Want the full story? Read the original article
Read on BleepingComputer