Malicious Ads on Bing Promote Fake Claude App, Delivering SectopRAT Malware to Over 29 Organizations
In a disturbing example of how malicious ads can compromise even the most trusted online services, researchers at Huntress have uncovered a malvertising campaign on Microsoft’s Bing search platform. This operation, dubbed “FakeAgent,” has been pushing a fake installer for the popular Claude desktop app, which in reality delivers the notorious SectopRAT malware to unsuspecting users.
According to Huntress, between July 21-22, at least 29 organizations fell victim to this malicious campaign, highlighting the potential for widespread damage. The attackers exploited a common tactic: using a legitimate domain to host malicious content. In this case, they used a Claude Artifact hosted on Claude’s own domain, which was downloaded over 7,100 times before it was eventually removed by Anthropic.
The SectopRAT malware, recently observed being distributed via CastleLoader campaigns and ClickFix attacks, uses the EtherHiding technique to retrieve a working command-and-control (C2) address via Ethereum BNB Smart Chain transactions. This sophisticated malware has been active since 2019 and is an information-stealer with HVNC functionality, allowing remote hands-on operations and real-time interaction with compromised systems.
The infection chain features various loaders and staging components that employ anti-analysis mechanisms, including VMProtect packing, shader timing checks, GPU and VRAM checks, and virtual machine (VM) detection. Upon delivery, the SectopRAT malware targets user passwords, credit card data, files, browser logins and cookies, FTP credentials, data from messaging clients, Steam, and VPN products.
In a surprising twist, Huntress used Claude Opus 4.8 to assist with shader emulation, cryptographic reconstruction, and .NET code analysis. This allowed them to attribute the attacks to SectopRAT operations or a closely related fork and gain insight into the infrastructure behind the campaign. However, despite their efforts, Huntress was unable to pinpoint the specific threat cluster responsible for this operation.
The implications of this discovery are clear: users should exercise extreme caution when downloading software, especially from search results or sponsored links. Trusting official websites and download portals is essential in preventing similar attacks. As security teams continue to battle sophisticated threats, it’s crucial to test every layer of defense before attackers do – a lesson reinforced by the Picus whitepaper on breach and attack simulation.
For individual users, this incident serves as a timely reminder to be vigilant when searching for software online. By prioritizing official sources and verifying downloads, we can collectively reduce the risk of falling victim to malicious campaigns like FakeAgent.
Source: Bleeping Computer — 2026-07-23