A FakeAgent campaign is using malicious search advertisements and counterfeit Claude Desktop download pages to deliver the SectopRAT remote-access trojan to Windows users. The trojanized installer reportedly executes PowerShell to add Microsoft Defender exclusions, then uses DLL sideloading via a signed Java Chromium Embedded Framework helper and creates a disguised elevated scheduled task for persistence. Associated indicators include Claude-themed download infrastructure, lookalike application components, and IP address 153.75.84.173.
SectopRAT retrieves encrypted connection information through EtherHiding, using Ethereum blockchain data instead of a conventional command-and-control server. Organizations should isolate potentially affected endpoints, identify and remove unauthorized Defender exclusions and scheduled tasks, revoke credentials and active sessions used on exposed hosts, review identity activity, and reimage systems where execution is confirmed.

Get the infrastructure and lures behind it.
3 events from the most recent confirmed update back to the earliest known activity.
Responders isolated the affected device, removed unauthorized Defender exclusions, revoked user sessions, reset credentials, and reimaged the endpoint. They also reviewed identity and access activity to determine whether stolen credentials had been used elsewhere.
The malware created an elevated logon-triggered scheduled task named MicrosoftEdgeUpdate that launched a staged DockerDesktop.exe loader from a user-writable roaming-profile directory. SectopRAT retrieved encrypted connection details using EtherHiding and Ethereum blockchain data rather than a fixed conventional command-and-control server.
A campaign assessed as FakeAgent used malicious search advertisements and spoofed Claude desktop download pages to deliver trojanized Windows installers, culminating in the SectopRAT remote-access trojan. The installers used PowerShell to add Microsoft Defender exclusions and DLL sideloading through a signed Java Chromium Embedded Framework helper.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 9 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
2 references tracked. Mallory keeps watching after this page renders.
cryptika.com
Open sourcecybersecuritynews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.