bleeping-computer · Crawled Jul 23, 2026

Fake Claude app promoted by Bing ads pushes SectopRAT malware

3 IoCs 1 Malware
Read original article ↗

AI Summary

A malvertising campaign leveraging Bing ads promotes a fake Claude desktop application to distribute the SectopRAT remote access trojan. The malicious installer, ClaudeDesktop.exe, sideloads a malicious DLL to deploy the malware, which establishes persistence via a scheduled task under the name DockerDesktop.exe. SectopRAT, also known as ArechClient2, steals credentials, files, and sensitive data from browsers and messaging apps, using Ethereum transactions to retrieve C2 addresses. The campaign, dubbed FakeAgent, has compromised at least 29 organizations and uses anti-analysis techniques to evade detection.

AI-extracted · verify before operational use

Extracted Entities 1 found

Indicators of Compromise 3 extracted

Type Value Detail
Filename ClaudeDesktop.exe Details →
Filename libcef.dll Details →
Filename DockerDesktop.exe Details →

MITRE ATT&CK TTPs 15 techniques