Malvertising campaign 'FakeAgent' spreads SectopRAT malware via fake Claude desktop app on Bing ads
Attackers used Bing search ads to distribute a fake 'ClaudeDesktop.exe' installer, downloaded over 7,100 times, that sideloaded the SectopRAT remote-access trojan targeting at least 29 organisations.
- Security & misuse
- Minor
Security researchers at Huntress documented a malvertising campaign, named FakeAgent, that bought sponsored Bing search results to push a fake Claude desktop installer, ClaudeDesktop.exe. Some versions of the campaign hosted the malicious payload as a Claude Artifact on Anthropic’s own claude.ai domain, lending it the appearance of a legitimate download. The installer was downloaded roughly 7,100 times before Anthropic removed the offending artifact, and Huntress said at least 29 organisations had been compromised between 21 and 22 July 2026.
The payload was SectopRAT, a remote-access trojan that harvests browser credentials, payment data and messaging-app information, and which used the EtherHiding technique — retrieving its command-and-control address from transactions on the BNB Smart Chain — to make takedown harder. Huntress traced infrastructure links to earlier campaigns distributing the StealC malware family and domains registered from December 2025 onward, but said it had insufficient evidence to attribute FakeAgent to a specific known actor.
The campaign followed a pattern familiar from fake ChatGPT browser extensions in 2023: as an AI product becomes something people actively search for and want to install, its name becomes bait for search-ads abuse regardless of how the underlying company itself handles security. Huntress noted the incident’s other detail — that it used Claude to help reverse-engineer the malware it was named after — as illustrative of the same tools now sitting on both sides of that fight.