Find notable cyber news and cases, enriched with sources, timelines, and signals.

SectopRAT fake Claude installer delivery

Malware Activity
First reported
Last updated
Happening score
H score 19
1 unique sources, 1 articles

Summary

Hide ▲

The SectopRAT malware is being delivered through a fake Claude desktop installer, exposing at least 29 organizations to credential theft and remote hands-on control. The infection chain uses a legitimate Claude.ai domain and a malicious Claude Artifact to redirect targets toward a counterfeit ClaudeDesktop.exe download. A legitimate JetBrains Chromium component then sideloads libcef.dll to launch the trojan. The malware also adds persistence, making the compromise harder to remove.

Related Happenings

FakeAgent Bing malvertising campaign pushing fake Claude installer

Campaign
H score25 First: 23.07.2026 22:48 Last: 23.07.2026 22:48 Sources 1

How related: A malvertising campaign on the Bing search service is pushing a fake Claude desktop app installer hosted on a legitimate Claude.ai domain to deliver the SectopRAT malware.

About this happening: The FakeAgent malvertising campaign is using Bing search ads and a malicious Claude Artifact to push a fake Claude desktop installer, exposing organizations to S...

Fake Claude Code installation-page infostealer campaign targeting developers

Campaign
H score33 First: 11.05.2026 17:00 Last: 11.05.2026 17:00 Sources 1

About this happening: A fake Claude Code installer campaign is using sponsored search results and operator-controlled domains to deliver an infostealer to developer workstations, pu...

Fake Claude PlugX phishing campaign

Campaign
H score34 First: 13.04.2026 12:52 Last: 13.04.2026 12:52 Sources 1

About this happening: A February phishing campaign used a fake Claude website and fake meeting invitations to deliver PlugX malware to recipients, turning a popular AI brand into a malw...

Latest development: 07.05.2026 13:02

A fake Claude AI site at claude-pro[.]com distributed Claude-Pro-windows-x64.zip, which drops NOVupdate.exe, NOVupdate.exe.dat, and avk.dll to sideload DonutLoader and load the Beagle backdoor on Windows. The backdoor uses license[.]claude-pro[.]com for command-and-control over TCP 443 and/or UDP 8080, and related Beagle samples were submitted to VirusTotal between February and April this year.

InstallFix Claude Code malvertising campaign

Campaign
H score32 First: 06.03.2026 17:00 Last: 06.03.2026 17:00 Sources 1

About this happening: InstallFix is being used in an active malvertising operation that pushes cloned Claude Code install pages and malicious CLI instructions, putting users who search for...

OpenClaw fake installer GitHub campaign promoted by Bing AI

Campaign
H score36 First: 06.03.2026 00:37 Last: 06.03.2026 00:37 Sources 1

About this happening: A last month campaign used fake OpenClaw installers on GitHub and Bing AI-promoted search results to push malware loaders and infostealers to people trying...

Latest development: 09.03.2026 20:31

A malicious npm package named @openclaw-ai/openclawai, uploaded on March 3, 2026, masquerades as an OpenClaw installer and uses a postinstall hook to launch scripts/setup.js, display a fake CLI and iCloud Keychain prompt, and fetch a second-stage payload from trackpipe[.]dev. The chain installs a persistent RAT internally identified as GhostLoader and steals macOS Keychain data, browser credentials, crypto wallets, SSH keys, Apple Notes, iMessage history, Safari history, and Mail data before exfiltrating a tar.gz archive through the C2 server, Telegram Bot API, and GoFile.io.

Timeline

  1. 23.07.2026 22:48 2 articles · 0h ago

    Bing malvertising pushes fake Claude desktop installer that delivers SectopRAT

    Initial Disclosure

    A malvertising campaign on the Bing search service pushed a fake Claude desktop app installer from a legitimate Claude.ai domain to deliver SectopRAT, and Huntress said the FakeAgent operation compromised at least 29 organizations between July 21-22. The malicious Claude Artifact was downloaded 7,100 times before Anthropic removed it, and the fake ClaudeDesktop.exe led to a legitimate JetBrains Chromium component that sideloaded libcef.dll to launch the trojan.

    Show sources