Fake Claude app promoted by Bing ads pushes SectopRAT malware
Attackers are leveraging malicious Bing ads and a fake Claude app to deploy SectopRAT malware across multiple corporate organizations.
Velocity
How fast coverage is spreading — measured hourly from article rate × source diversity. How this works →
The brief
A cyber campaign known as FakeAgent is targeting corporate users by promoting a fraudulent Claude desktop application through Bing advertisements. According to reports from BleepingComputer and TechRound, these ads lead victims to a fake download page that distributes SectopRAT, a type of data-stealing malware. The attack is sophisticated in its delivery, as Help Net Security reports that attackers managed to host the fake download page directly on the claude.ai domain. This deceptive infrastructure is designed to trick users into believing they are downloading official software from the legitimate service provider. Coverage from IT Security Guru and TechRound emphasizes the scale of the impact, noting that the campaign has already hit 29 different organizations.
These outlets highlight that the primary goal of the operation is the distribution of the SectopRAT malware to corporate environments. TechRadar further specifies that hackers achieved this by hiding the dangerous malware on a page that was concealed within the Anthropic-owned claude.ai domain. This specific detail underscores a critical vulnerability or exploitation method used to bypass user suspicion by utilizing a trusted domain to deliver the payload. Context provided by CyberSecurityNews indicates that the FakeAgent campaign specifically utilizes Claude.ai artifacts to infect its targets. The intersection of search engine advertising and the exploitation of a high-profile AI domain makes this a particularly potent threat.
Because corporate users often trust established AI tools, the use of Bing ads to drive traffic to a fake app on a legitimate-looking domain increases the likelihood of successful infection. The use of a Remote Access Trojan (RAT), specifically SectopRAT, indicates a goal of persistent access and data theft from the affected corporate entities. Future monitoring will focus on how the 29 impacted organizations respond to the breach and whether further instances of the fake download page are discovered on the claude.ai domain. Based on the reporting from Help Net Security and BleepingComputer, the primary point of interest is the mechanism that allowed the fake page to exist on the official domain. Observers will be looking for updates on whether more organizations are identified as victims of the FakeAgent campaign and if the malicious Bing ads have been fully removed from the search engine's ecosystem.
Synthesized by PULSE from the headlines below under a strict no-invention contract. ✓ fact-checked: all claims supported by sources Updated 2h ago.
Quick answers
What malware is being distributed in the FakeAgent campaign?
The campaign is distributing SectopRAT, which is described as data-stealing malware.
How are the victims lured into downloading the fake app?
Victims are targeted via malicious Bing advertisements that lead them to a fake Claude desktop download page.
How many organizations have been affected so far?
According to IT Security Guru and TechRound, 29 organizations have been hit by the malware.
Coverage (6)
- FakeAgent Campaign Uses Malicious Bing Ads and Claude.ai Artifacts to Infect Corporate Users CyberSecurityNews · 2d ago
- FakeAgent Campaign: Malicious Claude Artifact Used to Distribute SectopRAT to 29 Organisations IT Security Guru · 2d ago
- How attackers hosted a fake Claude download page on the claude.ai domain Help Net Security · 2d ago
- Fake Claude Desktop Ads Hit 29 Organisations With Data-Stealing Malware TechRound · 2d ago
- Hackers hid dangerous malware on a page hidden in Anthopic's Claude.ai domain TechRadar · 2d ago
- Fake Claude app promoted by Bing ads pushes SectopRAT malware BleepingComputer · 2d ago
Topics
Related trends
Anthropic launches Opus 5
Anthropic introduces Claude Opus 5, a cost-efficient AI model designed for coding, agents, and enterprise workflows as the company prepares for an IPO.
Anthropic updates Claude voice mode with more capable models
Anthropic has enhanced Claude's voice mode by integrating its more powerful Opus and Sonnet models for smarter, faster interactions.
Experts say exploiting Anthropic’s Fable isn’t how Kimi K3 got so good
5 news sources are covering this Business story right now — PULSE is tracking how fast it spreads.
OpenAI President Says Kimi K3 ‘Pretty Good,’ Unsure If Distilled
OpenAI's president reacts to the Kimi K3 model as international coverage tracks surging market shockwaves.
White House Official Says Moonshot Accessed Banned Nvidia Chips
The White House is accusing Chinese startup Moonshot of illegally accessing banned Nvidia chips and distilling an Anthropic AI model.
Exclusive | AMD and Anthropic Sign Major Chips-and-Investment Deal
AMD signs an exclusive chips-and-investment deal with Anthropic, committing up to $5 billion.