bleeping-computer · Crawled Jul 23, 2026
Fake Claude app promoted by Bing ads pushes SectopRAT malware
3 IoCs 1 Malware
Read original article ↗
AI Summary
A malvertising campaign leveraging Bing ads promotes a fake Claude desktop application to distribute the SectopRAT remote access trojan. The malicious installer, ClaudeDesktop.exe, sideloads a malicious DLL to deploy the malware, which establishes persistence via a scheduled task under the name DockerDesktop.exe. SectopRAT, also known as ArechClient2, steals credentials, files, and sensitive data from browsers and messaging apps, using Ethereum transactions to retrieve C2 addresses. The campaign, dubbed FakeAgent, has compromised at least 29 organizations and uses anti-analysis techniques to evade detection.
AI-extracted · verify before operational use
Extracted Entities 1 found
Indicators of Compromise 3 extracted
MITRE ATT&CK TTPs 15 techniques
T1001.003 Protocol or Service Impersonation · Command And Control T1014 Rootkit · Defense Evasion T1027 Obfuscated Files or Information · Defense Evasion T1053.005 Scheduled Task · Execution T1059.001 PowerShell · Execution T1071.001 Web Protocols · Command And Control T1071.003 Mail Protocols · Command And Control T1071.004 DNS · Command And Control T1082 System Information Discovery · Discovery T1090 Proxy · Command And Control T1114 Email Collection · Collection T1120 Peripheral Device Discovery · Discovery T1497 Virtualization/Sandbox Evasion · Defense Evasion T1539 Steal Web Session Cookie · Credential Access T1555 Credentials from Password Stores · Credential Access