Bottom line: Attackers use Bing ads and the claude.ai domain to distribute a counterfeit Claude installer containing SectopRAT malware to compromise systems.
A malvertising campaign leverages Bing ads to promote a fake Claude Desktop application hosted on a legitimate Claude.ai domain and delivers SectopRAT malware. This attack vector exploits the high trust in legitimate services and deceives users through ad placements on major search engines.
Security researchers have identified a malvertising campaign distributed via Bing search ads. The ads promote a fake Claude Desktop app installer hosted on what appears to be a legitimate Claude.ai domain. The downloaded file installs the SectopRAT malware on the victim’s system.
The tactic exploits multiple trust mechanisms: Bing ads are regarded as trustworthy ad placements, the domain belongs to Anthropic (the operator of Claude), and the application itself presents as a legitimate AI chat client. Users searching for “Claude download” or similar terms are specifically directed to the manipulated installer file.
SectopRAT is a remote access trojan family that grants attackers full control over compromised systems. This makes the campaign relevant to CISOs, as employees routinely install popular AI tools like Claude, creating a new attack surface. Organizations should update their awareness programs and consider regulating the installation of desktop applications from search results.
It is recommended to download software only from official sources—in Claude’s case directly from claude.ai—and to use browser plugins or security extensions that flag fake or manipulated download pages.
Source: www.bleepingcomputer.com · Published 23 July 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.