logo

FakeAgent Campaign Uses Malicious Bing Ads and Claude.ai Artifacts to Infect Corporate Users

ID: 60a3621a-ab61-552f-a36b-e44bef2480d3

STIX ID: report--60a3621a-ab61-552f-a36b-e44bef2480d3

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-07-24

Date Updated: 2026-07-24

Author: Tushar Subhra Dutta

...
...

Huntress researchers describe the FakeAgent campaign (July 2026) that lures corporate users via malicious paid Bing ads and a Claude.ai public Artifact to download a trojanized installer (ClaudeDesktop.exe/DockerDesktop.exe). The installers perform DLL sideloading and staged decryption using GPU shaders to deploy SectopRAT, an infostealer that harvests browser credentials, cookies, credit card data and files, and retrieves C2 configuration from Ethereum contracts; the report includes numerous domains, IPs, file hashes and recommended mitigations such as verifying vendor sites, monitoring for the listed filenames and scheduled tasks, and restricting admin rights.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.