A malvertising campaign dubbed FakeAgent abused searches for the Claude Desktop app to deliver the SectopRAT information-stealing trojan to Windows users at at least 29 organizations. Victims who clicked sponsored Bing results were sent to a spoofed public artifact hosted on Anthropic's claude.ai domain instead of the legitimate download page, then redirected to attacker-controlled infrastructure that served a fake ClaudeDesktop.exe installer. Huntress said the activity ran from July 21 to 22 and should be treated as a full remote-access and credential-theft compromise, not a nuisance adware incident.
The malware chain used DLL sideloading through a tampered libcef.dll, signed-binary proxy execution, VMProtect packing, GPU-based anti-analysis, and DirectX shader-based payload decryption to evade detection. Researchers said SectopRAT established persistence with sslconf.exe, tempdir.dll, and appcfg.dat under AppData, and retrieved command data via blockchain infrastructure tied to contract 0xc1907d7be91f95903ad66d775c397302e7dd9228; Huntress also identified 2.24.131[.]246 as a live command-and-control address. The RAT is capable of stealing browser credentials, cookies, autofill and payment data, Chromium keys, FTP credentials, Discord and messaging data, files, and passwords, and the infrastructure was linked to earlier malicious activity dating to May 2025, including domains associated with campaigns tied to StealC infrastructure seized during Operation Endgame.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Help Net Security reports Huntress said the malicious public Claude Artifact used in the FakeAgent campaign was viewed 7,100 times before Anthropic removed it. This reflects a concrete response action by the platform following the abuse of the claude.ai domain.
Huntress linked infrastructure used in the FakeAgent campaign to prior malicious activity dating back to May 2025, including domains associated with earlier campaigns and infrastructure tied to StealC activity seized during Operation Endgame.
On July 22, 2026, Huntress reported the FakeAgent campaign, describing how a malicious public Claude artifact was used to distribute SectopRAT through a fake ClaudeDesktop.exe installer and attacker-controlled redirection chain.
Between July 21 and July 22, 2026, victims searching Bing for the Claude Desktop app clicked sponsored ads that led to a spoofed Claude Artifact and attacker-controlled infrastructure, resulting in SectopRAT infections. Huntress said at least 29 organizations were affected.
Operation Endgame publicly identified and seized infrastructure associated with StealC activity. Huntress later cited this seized infrastructure as part of the historical infrastructure overlap connected to the FakeAgent campaign.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
trojan-killer.net
Open sourceitsecurityguru.org
Open sourcehelpnetsecurity.com
Open sourcebleepingcomputer.com
Open sourceoperation-endgame.com
Open sourcehuntress.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.