A malvertising campaign on Bing is using a fake Claude desktop app installer hosted on a legitimate Claude.ai domain to spread SectopRAT malware. Researchers say the FakeAgent operation compromised at least 29 organizations and used anti-analysis tricks, malicious loaders, and EtherHiding-based C2 retrieval to support the infection chain. #Claude #SectopRAT #FakeAgent #Huntress #Anthropic
Keypoints
- A Bing malvertising campaign pushed a fake Claude installer to deliver SectopRAT.
- The malware was hosted through a malicious Claude Artifact on the legitimate Claude.ai domain.
- At least 29 organizations were compromised during the FakeAgent operation.
- The infection chain used DLL sideloading, scheduled tasks, and anti-analysis techniques.
- SectopRAT steals credentials and uses EtherHiding to obtain command-and-control addresses.