Malicious Claude.ai Artifact Served by Bing Ads Delivered SectopRAT to 29 Organizations
The incident shows user-published pages on trusted domains can host convincing download lures with blockchain-hidden command links that resist takedown.
Overview
- Huntress says the FakeAgent malvertising run took place July 21–22, 2026 and used sponsored Bing results that led users to a public Claude Artifact on claude.ai which mimicked the Claude Desktop installer and infected at least 29 organizations.
- Clicking the spoofed download routed victims through attacker-controlled sites to a bundle that ran a signed JetBrains binary vulnerable to DLL sideloading, loaded a tampered libcef.dll carrying the payload, and dropped a DockerDesktop.exe that was registered as a scheduled task for persistence.
- The payload was SectopRAT, an information-stealing remote access trojan that harvests browser logins, autofill and payment data, files, and can provide remote interactive access to infected machines.
- Huntress’s analysis found layered evasion including VMProtect packing, GPU and shader timing checks, a shader-based decryption routine, and EtherHiding where command addresses are read from Ethereum/BNB transactions to make C2 harder to take down.
- Anthropic removed the malicious Artifact after roughly 7,100 views and Huntress published IOCs and a technical writeup while investigators traced domain registrations to an email linked to multiple domains since December 2025 including one seized during Operation Endgame, leaving open the risk of related activity.