Fake Claude app promoted by Bing ads pushes SectopRAT malware
Attackers are leveraging malicious Bing ads and a fake Claude app to deploy SectopRAT malware across multiple corporate organizations.
Velocity
How fast coverage is spreading — measured hourly from article rate × source diversity. How this works →
The brief
A cyber campaign known as FakeAgent is targeting corporate users by promoting a fraudulent Claude desktop application through Bing advertisements. According to reports from BleepingComputer and TechRound, these ads lead victims to a fake download page that distributes SectopRAT, a type of data-stealing malware. The attack is sophisticated in its delivery, as Help Net Security reports that attackers managed to host the fake download page directly on the claude.ai domain. This deceptive infrastructure is designed to trick users into believing they are downloading official software from the legitimate service provider. Coverage from IT Security Guru and TechRound emphasizes the scale of the impact, noting that the campaign has already hit 29 different organizations.
These outlets highlight that the primary goal of the operation is the distribution of the SectopRAT malware to corporate environments. TechRadar further specifies that hackers achieved this by hiding the dangerous malware on a page that was concealed within the Anthropic-owned claude.ai domain. This specific detail underscores a critical vulnerability or exploitation method used to bypass user suspicion by utilizing a trusted domain to deliver the payload. Context provided by CyberSecurityNews indicates that the FakeAgent campaign specifically utilizes Claude.ai artifacts to infect its targets. The intersection of search engine advertising and the exploitation of a high-profile AI domain makes this a particularly potent threat.
Because corporate users often trust established AI tools, the use of Bing ads to drive traffic to a fake app on a legitimate-looking domain increases the likelihood of successful infection. The use of a Remote Access Trojan (RAT), specifically SectopRAT, indicates a goal of persistent access and data theft from the affected corporate entities. Future monitoring will focus on how the 29 impacted organizations respond to the breach and whether further instances of the fake download page are discovered on the claude.ai domain. Based on the reporting from Help Net Security and BleepingComputer, the primary point of interest is the mechanism that allowed the fake page to exist on the official domain. Observers will be looking for updates on whether more organizations are identified as victims of the FakeAgent campaign and if the malicious Bing ads have been fully removed from the search engine's ecosystem.
Synthesized by PULSE from the headlines below under a strict no-invention contract. ✓ fact-checked: all claims supported by sources Updated 46d ago.
Quick answers
What malware is being distributed in the FakeAgent campaign?
The campaign is distributing SectopRAT, which is described as data-stealing malware.
How are the victims lured into downloading the fake app?
Victims are targeted via malicious Bing advertisements that lead them to a fake Claude desktop download page.
How many organizations have been affected so far?
According to IT Security Guru and TechRound, 29 organizations have been hit by the malware.
Coverage (6)
- FakeAgent Campaign Uses Malicious Bing Ads and Claude.ai Artifacts to Infect Corporate Users CyberSecurityNews · 48d ago
- FakeAgent Campaign: Malicious Claude Artifact Used to Distribute SectopRAT to 29 Organisations IT Security Guru · 48d ago
- How attackers hosted a fake Claude download page on the claude.ai domain Help Net Security · 48d ago
- Fake Claude Desktop Ads Hit 29 Organisations With Data-Stealing Malware TechRound · 48d ago
- Hackers hid dangerous malware on a page hidden in Anthopic's Claude.ai domain TechRadar · 48d ago
- Fake Claude app promoted by Bing ads pushes SectopRAT malware BleepingComputer · 48d ago
Topics
Related trends
Mathematicians want proof OpenAI didn’t use their work
A conflict has emerged between mathematicians and AI giants OpenAI and Anthropic regarding the usage of mathematical work in model training.
'Extinction' warnings ramp up as more OpenAI, Anthropic researchers join calls for an AI slowdown
Researchers from OpenAI and Anthropic are intensifying warnings about AI-driven extinction, sparking urgent legislative action in the U.S. Senate.
Anthropic reveals fourth likely crime committed by its AI
Anthropic has reported a fourth cybersecurity incident and revealed what is characterized as a fourth likely crime committed by an early version of Claude.
Newsom signs AI safety bills backed by Anthropic, OpenAI
California Governor Gavin Newsom has signed first-in-the-nation AI safety legislation backed by industry leaders OpenAI and Anthropic.
Anthropic discloses fourth AI hacking incident missed in earlier review
Anthropic discloses a fourth AI hacking incident involving Claude Opus 4.6 that was missed in an earlier review.
'Seems Like A Setup': Ex-Anthropic Staffer's Warnings On AI Extinction Risks Mocked By Musk.
Former Anthropic staffer warnings regarding artificial intelligence extinction risks face mocking remarks from Musk.