Hackers Use Fake Claude Desktop and Bing Ads to Deliver SectopRAT to 29 Organizations

Affected endpoints showed unusual Defender exclusions, new persistence mechanisms, and outbound connections aligned with remote access and credential theft activity, leading analysts to treat incidents as full RA T-level compromises rather than benign adware.

Huntress tracks this malvertising-driven operation as “FakeAgent,” highlighting the abuse of Claude’s own artifact hosting and the use of a fake Claude Desktop app as the lure.

The infection chain starts with users searching Bing for “Claude desktop app,” then clicking a sponsored result that appears to point to the legitimate Claude AI domain.

Instead of the official download page, victims are redirected to a malicious public Claude Artifact hosted at claude[.]ai/public/artifacts/ca456f1f-44c0-42af-b329-4f1c7534a877, which masquerades as a desktop installer and had been viewed roughly 7,100 times before Anthropic removed it.

Fake Claude Ads Deliver SectopRAT

From the Claude artifact, the “Download” button silently redirects users through claude.ai.download-app[.]us to downloading-api.it[.]com/html/claude/win, where they receive a trojanized ClaudeDesktop.exe.

Because the chain begins on a legitimate claude[.]ai page, many users implicitly trust the download, lowering resistance to execution.

The attackers use two primary binaries, ClaudeDesktop.exe and DockerDesktop.exe, which are functionally identical loaders. One executable runs immediately to stage the initial payload.

Claude Desktop/Cowork phishing page hosted as a Claude artifact (Source: huntress)
Claude Desktop/Cowork phishing page hosted as a Claude artifact (Source: huntress)

At the same time, the other is dropped as DockerDesktop.exe and registered as a scheduled task to provide persistent reinfection capability.

Importantly, ClaudeDesktop.exe is actually a JetBrains jcef_helper component misused for DLL sideloading, allowing a tampered libcef.dll to execute malicious code in the context of a trusted, signed binary.

The weaponized libcef.dll is packed with VMProtect, complicating static and dynamic analysis.

Embedded in this binary is a reference to an Ethereum contract (0xc1907d7be91f95903ad66d775c397302e7dd9228) that the malware uses to retrieve command-and-control data via the EtherHiding technique.

ClaudeDesktop.exe process details (Source: huntress)
ClaudeDesktop.exe process details (Source: huntress)

By encoding C2 information in blockchain transactions rather than hosting it directly on attacker infrastructure, the operators gain a resilient, takedown-resistant mechanism for rotating C2 endpoints.

Because SectopRAT provides both info-stealing and hidden remote desktop (HVNC-like) capabilities, organizations impacted by FakeAgent should assume full account takeover risk, credential theft, and potential hands-on-keyboard abuse of compromised systems.

Huntress recommends treating any host that executed the fake ClaudeDesktop.exe as fully compromised: rotating credentials, reviewing lateral movement, and rebuilding systems where appropriate.

Indicators of Compromise

TypeIndicatorDescription
URLclaude[.]ai/public/artifacts/ca456f1f-44c0-42af-b329-4f1c7534a877Malicious Claude Desktop download page
IP Address2.24.131[.]246Active SectopRAT C2 for FakeAgent campa

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Cut SOC investigation blind spots and contain threats earlier to reduce response costs and business disruption with ANY.RUN. 

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories