FakeAgent Campaign Uses Bing Ads to Deliver SectopRAT
The FakeAgent malvertising campaign used Bing search ads and a malicious Claude Artifact to distribute fake Claude desktop installers.
The campaign compromised at least 29 organizations between July 21 and July 22. Attackers delivered the SectopRAT remote access trojan, which can steal sensitive information and let operators control infected systems remotely.
Fake Claude Desktop Ads Appeared on Bing
FakeAgent attackers purchased Bing search ads that promoted a fraudulent Claude desktop application.
Users who clicked the sponsored results encountered content designed to resemble a legitimate Claude download. The campaign eventually directed victims to websites offering a file named ClaudeDesktop.exe.
Threat actors previously abused Bing AI Search to promote fake OpenClaw installers, showing how attackers continue to exploit search platforms and interest in popular AI applications.
Attackers Abused a Claude.ai Artifact
The campaign also used a malicious Claude Artifact hosted on the legitimate Claude.ai domain.
The Artifact reportedly received around 7,100 downloads before Anthropic removed it. Hosting the initial content on Claude.ai could make the campaign appear more trustworthy to users who recognized the legitimate domain.
The Artifact redirected visitors to external websites that distributed the fake ClaudeDesktop.exe installer.
Fake Installer Sideloaded a Malicious DLL
The downloaded package included a legitimate JetBrains Chromium component. Attackers used that trusted executable to sideload a malicious libcef.dll file from the same directory.
DLL sideloading allows malware operators to place a harmful library beside a legitimate application. When the trusted program starts, it loads the attacker-controlled DLL instead of the expected component.
The infection chain ultimately installed SectopRAT, a remote access trojan also tracked as ArechClient2.
Another executable named DockerDesktop.exe created a scheduled task to maintain persistence. This allowed the malware to run again after system restarts or user logins.
FakeAgent Used Multiple Anti-Analysis Checks
The malware chain included several techniques intended to slow security analysis and avoid automated detection.
These mechanisms included:
- VMProtect packing
- Shader timing checks
- GPU and video memory checks
- Virtual machine detection
The malware could use these checks to identify analysis environments or systems that did not resemble ordinary user devices.
SectopRAT Steals Data and Controls Systems
SectopRAT combines information-stealing capabilities with hidden remote-control functions.
Attackers can communicate with compromised computers in real time, execute commands and collect information from applications installed on the system.
The malware can target:
- Saved passwords and browser login credentials
- Browser cookies and stored credit card information
- Local files and FTP credentials
- Discord and Telegram data
- Steam account information
- VPN credentials and related data
The remote access features also allow operators to continue interacting with an infected device after the initial data collection.
Blockchain Transactions Reveal Active Control Servers
SectopRAT uses an approach known as EtherHiding to retrieve active command-and-control server addresses.
Instead of placing a fixed server address directly inside the malware, attackers store or reference infrastructure information through blockchain transactions. The malware can then retrieve updated addresses without requiring a new executable.
FakeAgent used Ethereum-related infrastructure on the BNB Smart Chain for this process.
This technique can make infrastructure disruption more difficult because defenders cannot remove blockchain transaction records in the same way they can take down a conventional website.
Researchers identified 10 domains registered with the same email address since December 2025.
The available evidence therefore shows a coordinated operation without establishing who operated it.
Users Should Avoid Software Offered Through Sponsored Results
Users should download Claude and other desktop applications only from verified official websites or trusted download portals.
Before opening an installer downloaded through a search engine, users should verify the website address, inspect the file name and digital signature, and scan the file with security software.
A few months earlier, attackers used another fake Claude AI download to distribute Beagle malware. Researchers also found that malicious GitHub repositories could manipulate Claude Code into running harmful commands.
Via BleepingComputer
Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more
User forum
0 messages