Affected endpoints showed unusual Defender exclusions, new persistence mechanisms, and outbound connections aligned with remote access and credential theft activity, leading analysts to treat incidents as full RA T-level compromises rather than benign adware.
Huntress tracks this malvertising-driven operation as “FakeAgent,” highlighting the abuse of Claude’s own artifact hosting and the use of a fake Claude Desktop app as the lure.
The infection chain starts with users searching Bing for “Claude desktop app,” then clicking a sponsored result that appears to point to the legitimate Claude AI domain.
Instead of the official download page, victims are redirected to a malicious public Claude Artifact hosted at claude[.]ai/public/artifacts/ca456f1f-44c0-42af-b329-4f1c7534a877, which masquerades as a desktop installer and had been viewed roughly 7,100 times before Anthropic removed it.
Fake Claude Ads Deliver SectopRAT
From the Claude artifact, the “Download” button silently redirects users through claude.ai.download-app[.]us to downloading-api.it[.]com/html/claude/win, where they receive a trojanized ClaudeDesktop.exe.
Because the chain begins on a legitimate claude[.]ai page, many users implicitly trust the download, lowering resistance to execution.
The attackers use two primary binaries, ClaudeDesktop.exe and DockerDesktop.exe, which are functionally identical loaders. One executable runs immediately to stage the initial payload.

At the same time, the other is dropped as DockerDesktop.exe and registered as a scheduled task to provide persistent reinfection capability.
Importantly, ClaudeDesktop.exe is actually a JetBrains jcef_helper component misused for DLL sideloading, allowing a tampered libcef.dll to execute malicious code in the context of a trusted, signed binary.
The weaponized libcef.dll is packed with VMProtect, complicating static and dynamic analysis.
Embedded in this binary is a reference to an Ethereum contract (0xc1907d7be91f95903ad66d775c397302e7dd9228) that the malware uses to retrieve command-and-control data via the EtherHiding technique.

By encoding C2 information in blockchain transactions rather than hosting it directly on attacker infrastructure, the operators gain a resilient, takedown-resistant mechanism for rotating C2 endpoints.
Because SectopRAT provides both info-stealing and hidden remote desktop (HVNC-like) capabilities, organizations impacted by FakeAgent should assume full account takeover risk, credential theft, and potential hands-on-keyboard abuse of compromised systems.
Huntress recommends treating any host that executed the fake ClaudeDesktop.exe as fully compromised: rotating credentials, reviewing lateral movement, and rebuilding systems where appropriate.
Indicators of Compromise
| Type | Indicator | Description |
|---|---|---|
| URL | claude[.]ai/public/artifacts/ca456f1f-44c0-42af-b329-4f1c7534a877 | Malicious Claude Desktop download page |
| IP Address | 2.24.131[.]246 | Active SectopRAT C2 for FakeAgent campa |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Cut SOC investigation blind spots and contain threats earlier to reduce response costs and business disruption with ANY.RUN.