Fake Claude App Pushes SectopRAT Malware Via Bing Malvertising
A sophisticated malvertising campaign leveraging **Bing** search ads is tricking users into downloading a malicious **Claude** desktop application. This fake installer, hosted on a legitimate **Claude.ai** domain, ultimately delivers the dangerous **SectopRAT** remote access trojan, compromising at least 29 organizations in a short span.
Cybersecurity researchers have uncovered a new malvertising campaign, dubbed **FakeAgent** by **Huntress**, that exploits **Bing** search results to distribute the potent **SectopRAT** malware. The attackers are pushing a deceptive **Claude** desktop app installer, surprisingly hosted on the legitimate **Claude.ai** domain, to deliver their malicious payload.
### Malvertising on Bing Leads to Malware
The campaign, active between July 21-22, has already led to the compromise of at least 29 organizations. The attackers leveraged a malicious **Claude Artifact**, a tactic previously seen earlier this year to push macOS malware via **ClickFix** lures.
**Huntress** reported that the malicious **Claude Artifact** was downloaded 7,100 times before **Anthropic** (the creator of **Claude**) removed it. This artifact redirected unsuspecting visitors to websites hosting a fake installer named `ClaudeDesktop.exe`.

### Deceptive Execution Chain
The `ClaudeDesktop.exe` file is not what it seems. It's a legitimate **JetBrains Chromium** component that is exploited to sideload a malicious DLL, `libcef.dll`. This DLL is the key to delivering the **SectopRAT** remote access trojan, which boasts extensive info-stealing capabilities.
Persistence on compromised systems is achieved through another executable, `DockerDesktop.exe`, which installs a scheduled task. **Huntress** notes that the various loaders and staging components in the infection chain incorporate anti-analysis mechanisms, including **VMProtect** packing, shader timing checks, GPU and VRAM checks, and virtual machine (VM) detection.
### SectopRAT: A Persistent Threat
**SectopRAT**, also known as **ArechClient2**, has been active since 2019. It's an information-stealer equipped with **HVNC** (Hidden Virtual Network Computing) functionality, allowing attackers remote hands-on operations and real-time interaction with compromised systems. The malware has recently been observed in **CastleLoader** campaigns and **ClickFix** attacks.
This sophisticated malware targets a wide array of sensitive data, including user passwords, credit card information, files, browser logins and cookies, FTP credentials, and data from messaging clients like **Discord** and **Telegram**, **Steam**, and various VPN products.
**SectopRAT** employs the **EtherHiding** technique to retrieve its command-and-control (C2) address, cleverly using **Ethereum BNB Smart Chain** transactions to conceal its communication.

### AI Assists in Analysis
In an interesting development, **Huntress** utilized **Claude Opus 4.8** to aid in their analysis, specifically for shader emulation, cryptographic reconstruction, and .NET code analysis. This AI assistance was crucial in decrypting the .NET payload (**SectopRAT**) and attributing the attacks to **SectopRAT** operations or a closely related fork, paving the way for infrastructure analysis.
During their infrastructure investigation, researchers discovered 10 domains registered to the same email address since December 2025. One of these domains was previously linked to **StealC** distribution and seized during **Operation Endgame**.
While **Huntress** does not have sufficient evidence to attribute the **FakeAgent** campaign to a specific, known threat cluster, the findings underscore the importance of vigilance.
### Recommendations for Users
Security professionals and privacy-conscious users are strongly advised to download software exclusively from official vendor websites and trusted download portals, rather than relying on search engine results, especially sponsored ones, which are increasingly exploited by malvertising campaigns.