Fake Claude app promoted by Bing ads pushes SectopRAT malware
A Bing malvertising campaign pushed a fake Claude desktop app that delivered SectopRAT malware, compromising at least 29 organizations in two days. The lure abused a legitimate Anthropic Claude.ai Artifact as its landing page.
Intelligence analysis by Llama

Attackers abused Bing sponsored results and a legitimate Anthropic-hosted Claude Artifact to distribute a trojanized ClaudeDesktop.exe, hitting 29 organizations with the SectopRAT info-stealer. Huntress traced infrastructure to a 2025 email-linked domain portfolio previously tied to StealC.
Bad guys put a fake Claude app download in Bing's paid ads, and the link even sat on Anthropic's real website. When 29 companies clicked, a sneaky program called SectopRAT stole their passwords and let attackers peek inside. It's like a thief dressing up as a mail carrier to walk straight into your house.
Analysis
Abusing Claude's Own Front Door
The FakeAgent campaign's most novel move is hosting the phishing lure on Claude.ai itself. Huntress found that attackers uploaded a malicious Claude Artifact — a legitimate content type on the Anthropic platform — that redirected roughly 7,100 visitors to external sites hosting a trojanized ClaudeDesktop.exe before Anthropic removed it. Because the link lived on a trusted Anthropic domain, traditional URL reputation checks and casual user inspection offered almost no warning.
A sponsored Bing result did the rest, putting the malicious link at the top of search pages for users hunting for a Claude desktop client. The combination of paid placement plus a claude.ai origin is precisely the kind of trust transfer attackers need to convert curiosity into compromise.
Inside the FakeAgent Infection Chain
The installer itself is layered. The exe is a legitimate JetBrains Chromium component that sideloads a malicious libcef.dll, which in turn drops SectopRAT and a persistence helper named DockerDesktop.exe that registers a scheduled task for survival across reboots. Huntress notes the loaders use VMProtect packing, shader timing checks, GPU and VRAM probes, and virtual machine detection — a heavier anti-analysis stack than is typical for stealer campaigns.
SectopRAT, tracked since 2019 and also known as ArechClient2, pairs info-stealing (browser logins, cookies, crypto wallets, FTP and messaging app data) with a Hidden VNC module for live hands-on access. The malware pulls its next-stage command-and-control address via the EtherHiding technique, reading it from BNB Smart Chain transactions — a blockchain-based dead drop that is far harder to take down than a conventional server.
Tracing the Operators
Attribution remains loose. Huntress used Anthropic's own Claude Opus 4.8 to reverse the .NET payload, reconstruct cryptography, and map infrastructure, then pivoted to 10 domains registered to a single email address since December 2025. One of those domains was previously linked to StealC distribution and was seized during Operation Endgame, but Huntress stops short of naming a specific threat cluster.
That gap matters operationally: without a clear group label, defenders have to block on tooling and behavior rather than indicators tied to a known actor. With 29 confirmed victims across just two days, the campaign is still hot, and security teams should treat any unexpected "Claude desktop" download as hostile until proven otherwise.
Key points
- At least 29 organizations were compromised in two days by a Bing ad campaign pushing a fake Claude desktop installer.
- Attackers hosted the lure as a malicious Claude Artifact on the legitimate claude.ai domain, which was downloaded roughly 7,100 times before takedown.
- The trojanized ClaudeDesktop.exe sideloads a malicious libcef.dll to drop SectopRAT and uses DockerDesktop.exe for persistence via a scheduled task.
- SectopRAT (aka ArechClient2) is an info-stealer with Hidden VNC capability and uses the EtherHiding technique on BNB Smart Chain to retrieve its C2 address.
- Huntress linked the campaign's infrastructure to 10 domains registered to one email since December 2025, one of which was previously tied to StealC and seized during Operation Endgame.
Anthropic's rapid takedown of the malicious Artifact and Huntress's public infrastructure map give defenders a head start on blocking the 10 associated domains. The incident is also likely to push Bing and other ad platforms to scrutinize sponsored results that redirect to executable downloads, raising the cost for future copycat campaigns.
Because SectopRAT retrieves its C2 address from a public blockchain, takedown efforts against the malware's infrastructure are likely to be short-lived and the operators can rotate quickly. The success of hosting a malicious payload on a claude.ai Artifact may also inspire copycats to abuse other trusted AI platforms the same way.



