Inside FakeAgent: How a Claude Desktop Malvertising Campaign Hit 29 Organizations with SectopRAT
ID: afd22c3e-fbe1-594e-aabc-87a75feb973f
STIX ID: report--afd22c3e-fbe1-594e-aabc-87a75feb973f
Feed Name: Huntress Blog
This Huntress analysis documents the 'FakeAgent' malvertising campaign (July 21–22, 2026) that lured victims to a malicious Claude.ai artifact hosting a fake Claude Desktop installer which deployed SectopRAT via DLL sideloading; the report details advanced evasion techniques (VMProtect packing, GPU/SM5 shader-based decryption, GPU anti-VM checks), EtherHiding (Ethereum/BSC-stored C2 data), recovered cryptomaterials and historical C2 IPs, and provides extensive IOCs (domains, hashes, smart contract addresses, and extracted C2 addresses).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
