A malvertising campaign on the Bing search service is pushing a fake Claude desktop app installer hosted on a legitimate Claude.ai domain to deliver the SectopRAT malware.
At least 29 organizations were compromised between July 21-22 during the malicious operation, which researchers call FakeAgent.
The attacker uses a malicious Claude Artifact hosted on Claude’s legitimate domain, which is a common tactic that has been used
The attackers used a malicious Claude Artifact hosted on Claude’s legitimate domain, a tactic that has been used at the beginning of the year to push macOS malware via ClickFix lures.
Researchers at managed security company Huntress found that the malicious Claude Artifact, downloaded 7,100 times before Anthropic removed it, directed visitors to websites that hosted a fake installer named ClaudeDesktop.exe.






