Fake Claude Desktop App on Bing Ads Spreads SectopRAT Malware: How the FakeAgent Campaign Works
Jul 24, 2026
Cybercriminals are once again abusing users' trust in popular AI tools. Researchers have uncovered a sophisticated malvertising campaign that uses sponsored Bing advertisements to distribute a fake Claude Desktop application, ultimately infecting victims with the SectopRAT remote access trojan.
The campaign, dubbed FakeAgent, demonstrates how threat actors are increasingly combining legitimate cloud platforms, paid advertisements, and convincing phishing techniques to bypass traditional security awareness.
According to Huntress researchers, the operation compromised at least 29 organizations within just two days, making it one of the most effective AI-themed malware campaigns observed this year.
Threat Type | Malvertising, Remote Access Trojan (RAT), Fake Software Installer |
|---|---|
Target | Windows users searching for Claude Desktop |
Malware | SectopRAT |
Attack Vector | Bing sponsored advertisements leading to fake Claude installer |
Affected Organizations | At least 29 organizations |
Researchers | Huntress |
Risk Level | High |
How the Attack Works
The attack begins with users searching Bing for "Claude Desktop App."
Instead of clicking an obviously suspicious website, victims encounter a sponsored advertisement pointing to the legitimate claude.ai domain. This significantly increases trust because the displayed destination appears authentic.
However, the advertisement does not lead to Anthropic's official download page.
Instead, it redirects users to a public Claude Artifact created by the attacker. Claude Artifacts are publicly shareable webpages hosted on the official Claude.ai domain, allowing attackers to abuse Anthropic's trusted infrastructure for phishing.
The fake page perfectly imitates Claude's download portal and convinces users to download a malicious installer named:
ClaudeDesktop.exe
Clicking the download button silently redirects users to attacker-controlled infrastructure that serves the malware payload.
Abuse of a Trusted Domain
One of the most dangerous aspects of this campaign is the abuse of Claude's own domain.
Because the phishing page is hosted under claude.ai, many traditional security controls and cautious users are less likely to question its legitimacy.
Although the page displayed a disclaimer stating that the content was user-generated and unverified, it was easy to overlook.
Before Anthropic removed the malicious Artifact after notification from Huntress, researchers estimate it had already received approximately 7,100 visits.
SectopRAT Infection Chain
After downloading the fake installer, victims unknowingly install SectopRAT, a sophisticated .NET-based remote access trojan.
Researchers observed several anti-analysis techniques designed to frustrate malware analysts, including:
VMProtect packing
Virtual machine detection
Graphics hardware checks
Multi-stage payload delivery
Blockchain-based command-and-control infrastructure
Once active, SectopRAT is capable of stealing:
Browser passwords
Credit card information
Authentication cookies
Cryptocurrency wallet data
Sensitive documents
Personal files
Stored credentials
The malware also establishes persistence to maintain long-term access to infected systems.
Timeline of the FakeAgent Campaign
Date | Event |
|---|---|
July 21–22, 2026 | Victims search Bing for Claude Desktop |
User clicks sponsored Bing advertisement | Redirected to malicious Claude Artifact |
Fake Claude download page displayed | Victim downloads ClaudeDesktop.exe |
Installer executed | SectopRAT payload installed |
Huntress investigation begins | Multiple organizations report similar activity |
Malicious Artifact reported | Anthropic removes public Artifact |
Why This Attack Is So Effective
Unlike traditional phishing campaigns that rely on suspicious domains or typo-squatting, FakeAgent exploits trusted infrastructure.
The campaign succeeds because it combines several high-confidence indicators:
Legitimate claude.ai domain
Sponsored Bing advertisement
Convincing software download page
Familiar AI branding
Minimal visible warning signs
This layered approach significantly increases the likelihood that users will trust the download.
It also highlights how attackers are adapting their tactics as AI applications become mainstream targets.
Indicators of Compromise
Organizations should monitor for:
Unexpected execution of ClaudeDesktop.exe
Downloads originating from unofficial Claude installer pages
New Windows Defender exclusions
Unknown persistence mechanisms
Outbound communication associated with SectopRAT infrastructure
Suspicious PowerShell or installer activity following browser downloads
Security teams should also educate users that legitimate software should only be downloaded from verified vendor pages rather than sponsored search advertisements.
Mitigation Recommendations
Organizations can reduce exposure to similar attacks by:
Blocking or restricting sponsored advertisement clicks for software downloads
Validating software download URLs before installation
Enforcing application allowlisting
Monitoring newly installed executables
Deploying endpoint detection and response (EDR) solutions
Training employees to recognize malvertising campaigns
Monitoring browser activity related to AI tool downloads
Since attackers increasingly abuse trusted cloud platforms, URL reputation alone is no longer sufficient to determine legitimacy.
Why This Matters
AI platforms have rapidly become attractive lures for cybercriminals.
Rather than creating entirely fake websites, attackers are increasingly abusing legitimate services to host malicious content, making traditional phishing indicators far less effective.
The FakeAgent campaign demonstrates that even trusted domains can become temporary malware distribution platforms when user-generated content is abused. As AI adoption continues to grow across enterprises, security teams should expect more campaigns leveraging familiar AI brands to deliver credential stealers, remote access trojans, and other malware families.






