Bing malvertising impersonates Claude to deliver SectopRAT malware

1 min read
Source: BleepingComputer
Bing malvertising impersonates Claude to deliver SectopRAT malware
Photo: BleepingComputer
TL;DR Summary

A Bing search malvertising campaign promoted a fake Claude desktop installer hosted on Claude.ai to deliver the SectopRAT information-stealer/HVNC malware, compromising at least 29 organizations on July 21–22. The fake ClaudeDesktop.exe loader hijacks a legitimate JetBrains Chromium component to load a malicious DLL, with persistence via a DockerDesktop.exe‑spawned scheduled task and multiple anti‑analysis checks. SectopRAT, active since 2019, exfiltrates credentials and supports remote control; the campaign also leveraged Claude Opus 4.8 for analysis. Researchers found about 10 domains tied to the same email since December 2025, but there isn’t enough evidence to link FakeAgent to a known threat group. The advisory advises downloading software only from official sources and avoiding sponsored results.

Share this article

Reading Insights

Total Reads

1

Unique Readers

7

Time Saved

3 min

vs 4 min read

Condensed

84%

691112 words

Want the full story? Read the original article

Read on BleepingComputer