Fake Claude App Promoted by Bing Ads Delivers SectopRAT Malware
A malvertising campaign is using Bing ads to distribute a fake Claude desktop application that installs the SectopRAT information-stealing malware.

A sophisticated malvertising campaign is leveraging Bing search advertisements to trick users into downloading a fake Claude desktop application, which ultimately installs the potent SectopRAT remote access trojan. The malicious installer was cleverly hosted on a legitimate Claude.ai domain, a tactic designed to enhance its credibility and bypass initial security checks. Researchers at Huntress discovered that this campaign, dubbed FakeAgent by the security community, compromised at least 29 organizations in a two-day period between July 21st and 22nd.
The attackers employed a malicious Claude Artifact, a component of the Claude AI service, to redirect unsuspecting users to a phishing page. This page hosted a deceptive installer named ClaudeDesktop.exe. While appearing to be a legitimate application installer, the file was actually a legitimate JetBrains Chromium component that, upon execution, sideloaded a malicious DLL (libcef.dll). This DLL was responsible for deploying the SectopRAT malware, an information-stealer with advanced remote access capabilities.
To ensure persistence on compromised systems, the malware establishes a scheduled task using an executable named DockerDesktop.exe. The infection chain incorporates several anti-analysis mechanisms, including VMProtect packing, shader timing checks, GPU and VRAM checks, and virtual machine detection, all intended to hinder security researchers and automated analysis tools. These sophisticated evasion techniques highlight the advanced nature of the threat actors involved.
SectopRAT, also known as ArechClient2, has been active since 2019 and is a versatile information-stealer. It possesses Hidden Virtual Network Computing (HVNC) functionality, enabling remote hands-on operations and real-time interaction with the victim's system. The malware is designed to exfiltrate a wide range of sensitive data, including user passwords, credit card details, browser logins and cookies, FTP credentials, and data from various messaging clients like Discord and Telegram, as well as VPN products.
Interestingly, the Huntress researchers utilized Claude Opus 4.8, the very AI service being impersonated, to aid in their analysis of the malware, specifically for shader emulation, cryptographic reconstruction, and .NET code analysis. This analysis of the decrypted .NET payload helped attribute the attacks to SectopRAT operations or a closely related variant.
Further investigation into the campaign's infrastructure revealed 10 domains registered to the same email address since December 2025. One of these domains had previously been linked to the distribution of StealC malware and was seized during the Operation Endgame takedown. Despite these links, Huntress has not yet attributed the FakeAgent campaign to a specific, known threat cluster.
This incident serves as a stark reminder for users to exercise extreme caution when downloading software, especially from search engine results, even when they appear legitimate. It is crucial to always verify the source and prioritize downloads directly from official vendor websites or trusted software repositories to avoid falling victim to such malvertising schemes.