logo

Fake Claude app promoted by Bing ads pushes SectopRAT malware

ID: 08495478-dbe3-5e58-bfcf-c60eb4c90491

STIX ID: report--08495478-dbe3-5e58-bfcf-c60eb4c90491

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2026-07-23

Date Updated: 2026-07-23

Author: Bill Toulas

...
...

A malvertising campaign called FakeAgent used a malicious Claude artifact hosted on a legitimate Claude.ai domain and promoted via Bing ads to push a fake ClaudeDesktop.exe that sideloads libcef.dll to deploy SectopRAT — an information-stealer with HVNC — resulting in at least 29 organizations compromised and roughly 7,100 downloads; the infection chain includes scheduled-task persistence (DockerDesktop.exe), anti-analysis measures, and an EtherHiding technique for C2 retrieval.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.