Find notable cyber news and cases, enriched with sources, timelines, and signals.

FakeAgent Bing malvertising campaign pushing fake Claude installer

Campaign
First reported
Last updated
Happening score
H score 25
1 unique sources, 1 articles

Summary

Hide ▲

The FakeAgent malvertising campaign is using Bing search ads and a malicious Claude Artifact to push a fake Claude desktop installer, exposing organizations to SectopRAT infections. At least 29 organizations were compromised during July 21-22, and the lure was downloaded 7,100 times before removal. The fake ClaudeDesktop.exe package sideloads libcef.dll to load the remote access trojan and steal data. The infection chain also uses DockerDesktop.exe for persistence and anti-analysis checks.

Related Happenings

SectopRAT fake Claude installer delivery

Malware Activity
H score19 First: 23.07.2026 22:48 Last: 23.07.2026 22:48 Sources 1

How related: However, the file is a legitimate JetBrains Chromium component that sideloads a malicious DLL (libcef.dll) to deliver the SectopRAT remote access trojan with info-stealing capabilities.

About this happening: The SectopRAT malware is being delivered through a fake Claude desktop installer, exposing at least 29 organizations to credential theft and remote hands-on control. T...

Fake Claude Code installation-page infostealer campaign targeting developers

Campaign
H score33 First: 11.05.2026 17:00 Last: 11.05.2026 17:00 Sources 1

About this happening: A fake Claude Code installer campaign is using sponsored search results and operator-controlled domains to deliver an infostealer to developer workstations, pu...

Fake Claude PlugX phishing campaign

Campaign
H score34 First: 13.04.2026 12:52 Last: 13.04.2026 12:52 Sources 1

About this happening: A February phishing campaign used a fake Claude website and fake meeting invitations to deliver PlugX malware to recipients, turning a popular AI brand into a malw...

Latest development: 07.05.2026 13:02

A fake Claude AI site at claude-pro[.]com distributed Claude-Pro-windows-x64.zip, which drops NOVupdate.exe, NOVupdate.exe.dat, and avk.dll to sideload DonutLoader and load the Beagle backdoor on Windows. The backdoor uses license[.]claude-pro[.]com for command-and-control over TCP 443 and/or UDP 8080, and related Beagle samples were submitted to VirusTotal between February and April this year.

Claude Code leak GitHub Vidar lure campaign

Campaign
H score32 First: 02.04.2026 23:30 Last: 02.04.2026 23:30 Sources 1

About this happening: A malicious GitHub repository campaign is abusing the Claude Code leak to deliver Vidar to users searching for leaked code. The lure uses a fake leak, search-eng...

Storm-2561 SEO-poisoning VPN credential-theft campaign

Campaign
H score37 First: 13.03.2026 15:38 Last: 13.03.2026 15:38 Sources 1

About this happening: The Storm-2561 group is running a credential-theft campaign that uses SEO poisoning and fake VPN clients to steal VPN credentials from people searching for ent...

Timeline

  1. 23.07.2026 22:48 2 articles · 0h ago

    FakeAgent campaign uses Bing ads to push a fake Claude installer

    Initial Disclosure

    Huntress identified a malvertising operation on the Bing search service, called FakeAgent, that used a malicious Claude Artifact on a legitimate Claude.ai domain to direct visitors to a fake ClaudeDesktop.exe installer and deliver SectopRAT. The campaign compromised at least 29 organizations between July 21-22, and the malicious Claude Artifact was downloaded 7,100 times before Anthropic removed it. The fake installer used a legitimate JetBrains Chromium component that sideloaded libcef.dll to load SectopRAT, while DockerDesktop.exe installed a scheduled task for persistence. Huntress also found anti-analysis checks in the loaders and staging components, including VMProtect packing, shader timing checks, GPU and VRAM checks, and VM detection, but said there was not enough evidence to attribute FakeAgent to a specific known threat cluster.

    Show sources