Bottom line: Malvertising campaign named FakeAgent used Bing ads and Anthropic’s Claude platform as a vector to distribute SectopRAT to at least 29 organizations.
Attackers leveraged manipulated Bing ads to infect at least 29 companies with the remote access trojan SectopRAT. The campaign directed users via fake Claude artifacts to prepared installation files.
Security researchers at Huntress uncovered a malvertising campaign running on Bing ads. The ads linked to a so-called Claude Artifact on the official domain claude.ai. This artifact was manipulated and led to an external page from which the file ClaudeDesktop.exe could be downloaded. The artifact was retrieved approximately 7,100 times before its removal by Anthropic.
The downloaded file was a legitimate Chromium component from JetBrains, but was abused for DLL sideloading. It loaded the malicious library libcef.dll, through which SectopRAT reached the target system. A second file named DockerDesktop.exe ensured persistence by creating a scheduled task in Windows Task Scheduler.
SectopRAT (also known as ArechClient2) is a remote access trojan with information-stealer capabilities that has been active since 2019. It offers Hidden Virtual Network Computing (HVNC) capabilities for direct real-time remote access. The malware targets passwords, credit card data, browser logins, cookies, FTP credentials, and data from messaging services such as Discord and Telegram. For command and control, it uses the EtherHiding method via transactions on the Ethereum BNB Smart Chain.
The campaign, designated FakeAgent, compromised at least 29 organizations between July 21 and 22. The loaders and intermediate stages deployed were protected with VMProtect encryption, graphics card and VRAM checks, as well as virtual machine detection techniques. Analysts identified ten server domains registered under the same email address since December 2025. One of these domains was previously active in the distribution of StealC and was seized as part of Operation Endgame. A confirmed attribution to a known threat actor group is not yet available.
Source: www.it-daily.net · Published July 26, 2026
Lumi AI News — AI-assisted curation pursuant to Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.