A Malvertising Campaign on Bing Exposes Users to SectopRAT Malware
A sophisticated malvertising campaign has been discovered on the Bing search service, which uses fake ads to promote a malicious Claude desktop app installer. This installer, hosted on a legitimate Claude.ai domain, delivers the notorious SectopRAT malware, capable of stealing sensitive user data and gaining remote access to compromised systems.
At least 29 organizations have fallen victim to this campaign, dubbed “FakeAgent” by researchers at Huntress, a managed security company. The attackers exploited a malicious Claude Artifact hosted on Claude’s legitimate domain, which was used to push macOS malware earlier this year via ClickFix lures. This tactic allows the attackers to leverage the trust associated with a well-known and reputable brand.
The malicious installer, masquerading as “ClaudeDesktop.exe,” is actually a legitimate JetBrains Chromium component that sideloads a malicious DLL (libcef.dll) to deliver the SectopRAT remote access trojan. Once installed, this malware enables persistence on the system through another executable named DockerDesktop.exe, which installs a scheduled task.
SectopRAT has been seen in various campaigns before, including CastleLoader and ClickFix attacks. This malware uses an innovative technique called EtherHiding to retrieve a working command-and-control (C2) address via Ethereum BNB Smart Chain transactions. Its capabilities include stealing sensitive data such as user passwords, credit card information, files, browser logins and cookies, FTP credentials, and data from popular messaging clients like Discord and Telegram.
In an unusual move, Huntress researchers used Claude Opus 4.8 to assist with analysis of the SectopRAT malware, employing shader emulation, cryptographic reconstruction, and .NET code analysis techniques. This helped attribute the attacks to a closely related fork of SectopRAT operations and opened up avenues for further infrastructure analysis.
While Huntress does not have enough evidence to link this campaign to a specific threat cluster, it’s clear that users are being targeted through malvertising on Bing. To avoid falling victim to such tactics, it’s essential to be cautious when downloading software, especially from search results or sponsored ads. Users should always trust official websites and download portals.
In the face of increasingly sophisticated threats like SectopRAT, security teams must stay vigilant and continuously test their systems for vulnerabilities. By doing so, they can prevent attacks from slipping through detection and protect their environments from potential breaches.
Source: Bleeping Computer — 2026-07-23