FakeAgent Campaign Uses Malicious Bing Ads and Claude.ai Artifacts to Infect Corporate Users
Key Takeaways A new malware campaign, dubbed “FakeAgent,” is targeting corporate users seeking a desktop version of the Claude AI assistant. The attackers leverage malicious Bing ads and...
Key Takeaways
- A new malware campaign, dubbed “FakeAgent,” is targeting corporate users seeking a desktop version of the Claude AI assistant.
- The attackers leverage malicious Bing ads and a seemingly legitimate Claude.ai “Artifact” page to distribute the SectopRAT malware.
- At least 29 organizations were impacted between July 21 and July 22, 2026, experiencing unusual software installations and persistent infections.
- SectopRAT is a potent remote access trojan capable of stealing sensitive data, including credit cards, passwords, browser information, and personal files.
- The campaign utilizes sophisticated anti-analysis techniques and EtherHiding for command-and-control infrastructure, making detection and takedown challenging.
A sophisticated new malware campaign, identified by researchers at Huntress, is exploiting the demand for AI desktop applications to compromise corporate systems. Dubbed “FakeAgent,” the campaign tricks users into downloading the potent SectopRAT remote access trojan by masquerading as a desktop version of the popular Claude AI assistant.
Table Of Content
Between July 21 and July 22, 2026, Huntress’s security operations center observed suspicious software installations and hidden persistence mechanisms across at least 29 organizations. These incidents were directly linked to employees searching for and attempting to install a Claude desktop application.
The Deceptive Infection Chain
The attack begins with malicious advertisements prominently displayed on Microsoft Bing. When users search for “CLAUDE DESKTOP APP,” sponsored results appear, designed to look like legitimate download links. A key element of the deception is an ad that directs users to an actual Claude.ai domain, specifically a public Artifact page. This tactic significantly reduces user suspicion, making the malicious link harder to identify.
Public Artifacts are user-generated pages hosted on the Claude.ai platform that can be shared publicly. While Claude itself carries a warning that content on these pages is unverified, the official domain hosting often leads users to trust the downloads without further scrutiny.
Clicking the “Download” button on the fraudulent Claude Artifact page initiates a redirect sequence, first to claude.ai.download-app.us and then to downloading-api.it.com. It is from this final domain that the malicious executable, named ClaudeDesktop.exe, is delivered to the victim’s system.
Malware Execution and Evasion
The downloaded ClaudeDesktop.exe is not the genuine Claude application. Instead, it is a renamed, signed JetBrains helper executable that performs a classic DLL sideloading attack. It loads a tampered library alongside itself, allowing malicious code to execute under the guise of a trusted process name. To ensure persistence, an identical copy of this loader, named DockerDesktop.exe, is later established as a scheduled task, enabling the infection to restart automatically after system reboots.
The attack chain further employs a second signed program, sslconf.exe, found within an EdgeUpdate folder. This program also loads an altered library. This stage incorporates advanced anti-analysis techniques, including checks for graphics hardware and video memory, designed to detect and evade virtualized environments and sandboxes. The hidden payload is then decrypted using a graphics shader, a method that leverages the GPU instead of the CPU, further complicating detection by traditional security tools. The ultimate payload delivered through this intricate process is SectopRAT.
SectopRAT is a powerful remote access trojan designed to exfiltrate a wide array of sensitive data. This includes browser logins, cookies, autofill data, credit card information, and data from messaging applications. The command-and-control (C2) addresses for SectopRAT are not hard-coded; they are dynamically pulled from Ethereum blockchain contracts, a technique known as EtherHiding. This method allows the threat actors to easily change C2 servers by posting new blockchain transactions, making the C2 infrastructure highly resilient to takedown efforts.
Operator Tactics and Mitigation
Huntress analysts noted that the operator behind the FakeAgent campaign has utilized similar tactics in previous attacks, including fake Docker Desktop lures and malicious shared Claude chats. This suggests a consistent modus operandi focused on leveraging popular software brands and search engine advertising to distribute malware.
Anthropic, the developer of Claude, has since removed the malicious Artifact identified by Huntress. However, the incident underscores a broader challenge: as more individuals and organizations adopt AI tools, both search engine advertising platforms and AI hosting features become attractive vectors for sophisticated malware campaigns. The malicious Artifact page had already garnered approximately 7,100 page views before its removal, highlighting the campaign’s potential reach.
What You Should Do
- Exercise Extreme Caution with Search Results: Never implicitly trust sponsored search results, especially when downloading software. Malicious ads can mimic legitimate ones.
- Verify Download Sources Directly: Always navigate directly to the official vendor’s website (e.g., anthropic.com for Claude) to download software. Do not rely on links from search engines or third-party sites.
- Monitor for Suspicious Processes: Security teams should actively monitor for unusual executable installs, particularly those named
ClaudeDesktop.exeorDockerDesktop.exe, outside of expected software deployment channels. - Inspect Scheduled Tasks and Defender Exclusions: Regularly audit scheduled tasks for new or unexpected entries and review antivirus exclusions for any unauthorized modifications.
- Implement Strong Endpoint Detection and Response (EDR): Utilize EDR solutions to detect and respond to suspicious activities, such as DLL sideloading and unusual process behaviors.
- Educate Users on Phishing and Malvertising: Conduct regular cybersecurity awareness training for employees, emphasizing the risks associated with downloading software from unverified sources and clicking suspicious ads.
- Keep Software Updated: Ensure all operating systems, applications, and security software are kept up-to-date with the latest patches to mitigate known vulnerabilities.
- Limit Administrative Privileges: Enforce the principle of least privilege, ensuring users and applications only have the necessary permissions to perform their functions.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.