FakeAgent Bing malvertising campaign pushing fake Claude installer
Campaign
Summary
Hide ▲
Show ▼
The FakeAgent malvertising campaign is using Bing search ads and a malicious Claude Artifact to push a fake Claude desktop installer, exposing organizations to SectopRAT infections. At least 29 organizations were compromised during July 21-22, and the lure was downloaded 7,100 times before removal. The fake ClaudeDesktop.exe package sideloads libcef.dll to load the remote access trojan and steal data. The infection chain also uses DockerDesktop.exe for persistence and anti-analysis checks.
Related Happenings
SectopRAT fake Claude installer delivery
Malware Activity
H score19
First: 23.07.2026 22:48
Last: 23.07.2026 22:48
Sources 1
How related:
However, the file is a legitimate JetBrains Chromium component that sideloads a malicious DLL (libcef.dll) to deliver the SectopRAT remote access trojan with info-stealing capabilities.
About this happening:
The SectopRAT malware is being delivered through a fake Claude desktop installer, exposing at least 29 organizations to credential theft and remote hands-on control. T...
SectopRAT fake Claude installer delivery
Malware ActivityHow related: However, the file is a legitimate JetBrains Chromium component that sideloads a malicious DLL (libcef.dll) to deliver the SectopRAT remote access trojan with info-stealing capabilities.
About this happening: The SectopRAT malware is being delivered through a fake Claude desktop installer, exposing at least 29 organizations to credential theft and remote hands-on control. T...
Fake Claude Code installation-page infostealer campaign targeting developers
Campaign
H score33
First: 11.05.2026 17:00
Last: 11.05.2026 17:00
Sources 1
About this happening:
A fake Claude Code installer campaign is using sponsored search results and operator-controlled domains to deliver an infostealer to developer workstations, pu...
Fake Claude Code installation-page infostealer campaign targeting developers
CampaignAbout this happening: A fake Claude Code installer campaign is using sponsored search results and operator-controlled domains to deliver an infostealer to developer workstations, pu...
Fake Claude PlugX phishing campaign
Campaign
H score34
First: 13.04.2026 12:52
Last: 13.04.2026 12:52
Sources 1
About this happening:
A February phishing campaign used a fake Claude website and fake meeting invitations to deliver PlugX malware to recipients, turning a popular AI brand into a malw...
Fake Claude PlugX phishing campaign
CampaignAbout this happening: A February phishing campaign used a fake Claude website and fake meeting invitations to deliver PlugX malware to recipients, turning a popular AI brand into a malw...
Latest development: 07.05.2026 13:02
A fake Claude AI site at claude-pro[.]com distributed Claude-Pro-windows-x64.zip, which drops NOVupdate.exe, NOVupdate.exe.dat, and avk.dll to sideload DonutLoader and load the Beagle backdoor on Windows. The backdoor uses license[.]claude-pro[.]com for command-and-control over TCP 443 and/or UDP 8080, and related Beagle samples were submitted to VirusTotal between February and April this year.
Claude Code leak GitHub Vidar lure campaign
Campaign
H score32
First: 02.04.2026 23:30
Last: 02.04.2026 23:30
Sources 1
About this happening:
A malicious GitHub repository campaign is abusing the Claude Code leak to deliver Vidar to users searching for leaked code. The lure uses a fake leak, search-eng...
Claude Code leak GitHub Vidar lure campaign
CampaignAbout this happening: A malicious GitHub repository campaign is abusing the Claude Code leak to deliver Vidar to users searching for leaked code. The lure uses a fake leak, search-eng...
Storm-2561 SEO-poisoning VPN credential-theft campaign
Campaign
H score37
First: 13.03.2026 15:38
Last: 13.03.2026 15:38
Sources 1
About this happening:
The Storm-2561 group is running a credential-theft campaign that uses SEO poisoning and fake VPN clients to steal VPN credentials from people searching for ent...
Storm-2561 SEO-poisoning VPN credential-theft campaign
CampaignAbout this happening: The Storm-2561 group is running a credential-theft campaign that uses SEO poisoning and fake VPN clients to steal VPN credentials from people searching for ent...
Timeline
-
23.07.2026 22:48 2 articles · 0h ago
FakeAgent campaign uses Bing ads to push a fake Claude installer
Initial DisclosureHuntress identified a malvertising operation on the Bing search service, called FakeAgent, that used a malicious Claude Artifact on a legitimate Claude.ai domain to direct visitors to a fake ClaudeDesktop.exe installer and deliver SectopRAT. The campaign compromised at least 29 organizations between July 21-22, and the malicious Claude Artifact was downloaded 7,100 times before Anthropic removed it. The fake installer used a legitimate JetBrains Chromium component that sideloaded libcef.dll to load SectopRAT, while DockerDesktop.exe installed a scheduled task for persistence. Huntress also found anti-analysis checks in the loaders and staging components, including VMProtect packing, shader timing checks, GPU and VRAM checks, and VM detection, but said there was not enough evidence to attribute FakeAgent to a specific known threat cluster.
Show sources
- Fake Claude app promoted by Bing ads pushes SectopRAT malware — www.bleepingcomputer.com — 23.07.2026 22:48
- Fake Claude app promoted by Bing ads pushes SectopRAT malware — www.bleepingcomputer.com — 23.07.2026 22:48