You search for "Claude" on Bing. The first result is a sponsored ad that takes you directly to a page hosted on Claude's official domain — claude.ai. The page looks exactly like a legitimate download portal. You download the installer. At that moment, a remote access trojan called SectopRAT takes control of your system.
This is not a hypothetical attack. Between 21 and 22 July 2026, at least 29 organisations were compromised through this technique, dubbed FakeAgent by the Huntress researchers who discovered it.
🔍 Suspicious message?
Analyze senders, links or files in real time with our scanner.
How the attack works
The entry vector has two layers that combine in an unusually effective way. The first is a paid advertisement on the Bing search engine that appears when someone searches for the Claude desktop app. The ad is visually indistinguishable from a legitimate result. The second layer is what makes this attack particularly notable: the fake download page was not hosted on a fraudulent domain — it was hosted on Claude's own official domain, claude.ai.
The attackers created a Claude Artifact — a legitimate feature that allows Claude users to create and share mini web applications — and configured it to look like an official download portal. The file was downloaded 7,100 times before Anthropic detected and removed it.
From that page, visitors downloaded an installer called ClaudeDesktop.exe. The file itself was a legitimate, digitally signed JetBrains component — which allowed it to bypass many antivirus products — but it came bundled with a malicious library (libcef.dll) that loaded automatically through DLL side-loading. Persistence on the system was established through another executable called DockerDesktop.exe, which installed a scheduled task.
What SectopRAT does once installed
SectopRAT, also known as ArechClient2, is a remote access trojan with infostealer capabilities that has been active since 2019. Once installed, it allows the attacker to remotely operate the compromised system in real time through HVNC (Hidden Virtual Network Computing) — a remote desktop connection completely invisible to the user.
The malware extracts passwords, cookies and credit card data from web browsers, FTP client credentials, cryptocurrency wallet data, Discord, Telegram and Steam tokens, and VPN product credentials. To locate its command-and-control server, it uses the EtherHiding technique — retrieving the active C2 address through transactions on the Ethereum BNB Smart Chain blockchain, which makes blocking the malicious communication significantly harder.
The infection chain components include multiple anti-analysis mechanisms: VMProtect packing, shader timing checks, GPU and VRAM verification, and virtual machine detection.
Why this attack is harder to detect than others
Most malvertising attacks direct victims to fake domains that impersonate legitimate ones — a detectable technique because the domain never exactly matches the original. FakeAgent removed that detection point: the download page was on claude.ai, Anthropic's real domain.
This illustrates an important tactical evolution. Attackers are learning to exploit the legitimate features of platforms themselves — in this case, Claude Artifacts — to host malicious content within trusted domains. The same mechanism was used earlier in 2026 to distribute macOS malware through ClickFix attacks.
Anthropic removed the malicious Artifact once notified, but during its active period (21-22 July) it had already compromised at least 29 organisations.
What signals to watch for
The first signal is the download channel. No legitimate desktop application should be downloaded from a sponsored search result. Official downloads are always on the manufacturer's website or in verified app stores — not in paid advertisements.
The second is the executable name. ClaudeDesktop.exe is not the name of Claude's official installer. Before running any installer, verify that the file name and digital signature match exactly what you would expect from the manufacturer.
The third is to distrust search engine ads for downloading software, regardless of the domain they lead to. An ad that appears above the organic result is not necessarily more legitimate — it is simply the one that paid the most to appear first.
The same old pattern in a new environment
FakeAgent is not a technically revolutionary attack. It is identity impersonation — someone pretending to be a legitimate tool to get you to run something you shouldn't. What changes is the channel: a paid ad on Bing plus a page hosted on a trusted domain. The combination makes the usual warning signs significantly harder to spot.
If you receive an email or a message with a link to download software — even if the domain looks legitimate — analyse it in ORTSLAB first before clicking. The engine detects fraudulent domains, phishing pages and social engineering patterns in seconds.