{"slug": "fakeagent-delivers-sectoprat-through-claude-desktop-lure", "title": "FakeAgent Delivers SectopRAT Through Claude Desktop Lure", "summary": "A Bing malvertising campaign used a malicious public Claude Artifact hosted on Anthropic's legitimate claude.ai domain to distribute the SectopRAT remote-access trojan, compromising at least 29 organizations between July 21 and July 22, according to Huntress. The fake installer, ClaudeDesktop.exe, sideloaded a malicious DLL, and the malware employed blockchain-based command-and-control discovery via the BNB Smart Chain. Huntress reported the artifact to Anthropic, and it was removed by July 22 after approximately 7,100 downloads.", "body_md": "# FakeAgent Delivers SectopRAT Through Claude Desktop Lure\n\nA Bing malvertising campaign used a malicious public Claude Artifact to distribute the SectopRAT remote-access trojan to at least 29 organizations between July 21 and July 22, according to Huntress. Victims searching for Claude Desktop were redirected to a fake installer that sideloaded a malicious DLL, while the malware used anti-analysis checks and blockchain-based command-and-control discovery.\n\nA Bing malvertising campaign used a malicious public Claude Artifact hosted on Anthropic's legitimate claude.ai domain to distribute the SectopRAT remote-access trojan, compromising at least 29 organizations between July 21 and July 22, according to Huntress. The security firm calls the operation FakeAgent.\n\nHuntress reported that victims searched for the Claude desktop application, clicked malicious Bing ads, and reached an attacker-created Claude Artifact. That artifact redirected visitors to attacker-controlled sites offering ClaudeDesktop.exe, a fake desktop installer. Huntress reported the artifact to Anthropic, and the artifact had been removed by July 22.\n\nBleepingComputer reports that the malicious Artifact was downloaded about 7,100 times before removal. The figure reflects exposure to the lure, not a confirmed count of successful infections.\n\n### DLL sideloading and persistence\n\nAccording to BleepingComputer's account of Huntress research, ClaudeDesktop.exe was a legitimate JetBrains Chromium component rather than an official Anthropic binary. The executable loaded a malicious libcef.dll through DLL sideloading, initiating delivery of SectopRAT.\n\nBleepingComputer reports that a second executable, DockerDesktop.exe, established persistence through a scheduled task. Huntress identified unusual executable installations, Microsoft Defender exclusions, and anomalous persistence activity across affected organizations.\n\nThe infection chain incorporated multiple anti-analysis controls, according to Huntress and BleepingComputer:\n\n- •VMProtect packaging to complicate reverse engineering.\n- •GPU, VRAM, graphics-adapter, and virtual-machine checks intended to identify analysis environments.\n- •Shader timing checks that can make behavior differ in virtualized or low-fidelity sandbox environments.\n- •Custom GPU-based decryption of an on-disk payload, as described by GBHackers from Huntress's technical analysis.\n\nHuntress also reported using Claude during its investigation to assist with shader emulation, cryptographic reconstruction, and .NET code analysis. That is distinct from the attackers' use of Claude's public Artifact hosting feature as a delivery redirect.\n\n### SectopRAT capabilities and infrastructure\n\nBleepingComputer describes SectopRAT, also known as ArechClient2, as an information stealer active since 2019 with hidden virtual network computing, or HVNC, functionality. HVNC can give an operator an isolated hidden desktop session for hands-on interaction with a compromised machine.\n\nAccording to BleepingComputer, the malware can target browser passwords, cookies, stored card data, files, FTP credentials, messaging-client data, Steam data, and VPN-product credentials. Huntress updated its original attribution to SectopRAT after identifying HVNC functionality in the decrypted .NET payload and examining related command-and-control services.\n\nThe malware uses the BNB Smart Chain to retrieve an active command-and-control address through blockchain transactions, BleepingComputer reports. This infrastructure-discovery mechanism can complicate conventional domain takedown and sinkholing because operators can update command-and-control information through on-chain data rather than relying on a static configuration.\n\n### Detection implications\n\nFor defenders, this incident combines a trusted-domain lure with signed or legitimate application components and staged DLL sideloading. Comparable campaigns often evade controls that focus primarily on domain reputation or simplistic executable allowlists, because the initial page and loader can appear superficially legitimate.\n\nHuntress's findings make endpoint telemetry especially relevant in this case: security teams can review executions of unexpected ClaudeDesktop.exe and DockerDesktop.exe files, DLL loads involving libcef.dll, newly created scheduled tasks, Defender exclusion changes, and suspicious outbound traffic following software downloads. Organizations should also reinforce verification of AI application downloads through official vendor distribution channels rather than sponsored search results or public artifacts.\n\n## Key Points\n\n- 1FakeAgent compromised at least 29 organizations by converting Bing searches for Claude Desktop into a SectopRAT delivery chain.\n- 2The campaign paired DLL sideloading with GPU and VM checks, illustrating how malware can frustrate commodity sandboxing and static analysis.\n- 3Blockchain-based command-and-control discovery can complicate takedowns, making endpoint behavior and persistence telemetry particularly important for detection.\n\n## Scoring Rationale\n\nThis is a notable active malware campaign that abuses a major AI platform's public hosting surface and affects enterprise endpoints. Its layered anti-analysis techniques, DLL sideloading, HVNC capability, and blockchain-based command-and-control discovery provide actionable detection and threat-hunting relevance for security and ML platform teams.\n\n## Sources\n\nPrimary source and supporting public references used for this report.\n\nPractice with real Ad Tech data\n\n90 SQL & Python problems · 15 industry datasets\n\n[Active Search Campaigns by BudgetEasy](/problems/sql/active-search-campaigns-by-budget)\n\n[High CPC Clicks & Poor Landing PagesMedium](/problems/sql/high-cpc-clicks-poor-landing-page)\n\n[Campaign ROAS by Attribution ModelHard](/problems/sql/campaign-roas-by-attribution-model)\n\n250 free problems · No credit card\n\n[See all Ad Tech problems](/problems/datasets/adtech)", "url": "https://wpnews.pro/news/fakeagent-delivers-sectoprat-through-claude-desktop-lure", "canonical_source": "https://letsdatascience.com/news/fakeagent-delivers-sectoprat-through-claude-desktop-lure-aa8314ca", "published_at": "2026-07-24 11:58:00+00:00", "updated_at": "2026-07-24 15:30:20.070973+00:00", "lang": "en", "topics": ["ai-safety", "ai-products"], "entities": ["Huntress", "Anthropic", "Claude Desktop", "SectopRAT", "Bing", "BleepingComputer", "JetBrains", "BNB Smart Chain"], "alternates": {"html": "https://wpnews.pro/news/fakeagent-delivers-sectoprat-through-claude-desktop-lure", "markdown": "https://wpnews.pro/news/fakeagent-delivers-sectoprat-through-claude-desktop-lure.md", "text": "https://wpnews.pro/news/fakeagent-delivers-sectoprat-through-claude-desktop-lure.txt", "jsonld": "https://wpnews.pro/news/fakeagent-delivers-sectoprat-through-claude-desktop-lure.jsonld"}}