Threat · curated 23 Jul 2026

Inside FakeAgent: How a Claude Desktop Malvertising Campaign Hit 29 Organizations with SectopRAT

Coverage timeline

discovered huntress.com primary 23 Jul 2026bleepingcomputer.com

Single-source incident — first reported, latest, and curated coincide.

Why it matters

Abuse of the trusted Claude.ai domain to host a phishing/download portal shows attackers weaponizing legitimate AI-platform features to bypass user suspicion and reputation filters, turning an AI service into a malware delivery channel.

A malvertising campaign dubbed FakeAgent used Bing ads and a malicious Claude Artifact hosted on Anthropic's legitimate Claude.ai domain to direct victims to a fake ClaudeDesktop.exe installer that sideloads a malicious libcef.dll to deploy the SectopRAT (ArechClient2) remote access trojan. Huntress reports at least 29 organizations were compromised between July 21-22, 2026, with the artifact downloaded 7,100 times before Anthropic removed it; the RAT steals credentials and uses EtherHiding on the BNB Smart Chain to fetch C2 addresses.