A sophisticated malvertising operation targeting Bing search users has successfully compromised at least 29 organizations by distributing a fake Claude desktop application that delivers SectopRAT malware. The campaign, which researchers have dubbed FakeAgent, conducted its attacks between July 21 and 22, 2026, exploiting trust in both the Bing advertising platform and the legitimate Claude.ai domain.
How Did Attackers Abuse Claude’s Legitimate Domain?
The threat actors employed a clever technique by hosting a malicious Claude Artifact on Claude’s authentic domain. This tactic mirrors methods used earlier in the year to distribute macOS malware through ClickFix lures. Security researchers at Huntress discovered that the malicious Artifact was downloaded approximately 7,100 times before Anthropic, Claude’s developer, successfully removed it from their platform.
The fraudulent Artifact redirected visitors to websites hosting a fake installer file called ClaudeDesktop.exe. Despite appearing to be a Claude application, the file was actually a legitimate JetBrains Chromium component that had been weaponized to sideload a malicious DLL file named libcef.dll, which then deployed the SectopRAT remote access trojan.
What Makes SectopRAT Dangerous?
SectopRAT, also identified as ArechClient2, has maintained operations since 2019 as an information-stealing trojan with Hidden Virtual Network Computing functionality. This capability enables attackers to conduct remote hands-on operations and interact with compromised systems in real-time. The malware maintains persistence through another executable called DockerDesktop.exe, which installs a scheduled task on infected machines.
The malware targets a wide range of sensitive information, including user passwords, credit card data, browser logins and cookies, FTP credentials, and data from messaging clients like Discord and Telegram. It also harvests information from Steam and VPN products. The infection chain incorporates sophisticated anti-analysis mechanisms, including VMProtect packing, shader timing checks, GPU and VRAM verification, and virtual machine detection.
How Does SectopRAT Communicate with Its Controllers?
SectopRAT employs the EtherHiding technique to retrieve working command-and-control addresses through Ethereum BNB Smart Chain transactions. This method has been observed in recent CastleLoader campaigns and ClickFix attacks distributing the same malware.
Huntress investigators utilized Claude Opus 4.8 to assist with technical analysis, including shader emulation, cryptographic reconstruction, and .NET code examination. Their infrastructure analysis uncovered 10 domains registered to the same email address since December 2025, with one domain previously linked to StealC distribution and subsequently seized during Operation Endgame. However, researchers lack sufficient evidence to attribute the FakeAgent campaign to a specific known threat group.
Source: BleepingComputer