Inside FakeAgent: How a Claude Desktop Malvertising Campaign Hit 29 Organizations with SectopRAT

Imported from official source

Cybersecurity Classified by Officially

Between July 21 and July 22, at least 29 organizations fell victim to a malvertising campaign that led them to a malicious Claude Artifact publicly hosted on the legitimate Claude.ai domain.

The malicious Claude Artifact redirected users to an attacker-controlled domain, where they downloaded what looks like a legitimate Claude desktop app (ClaudeDesktop.exe). In reality, the executable led to the download of SectopRAT.

The attackers used an array of anti-analysis techniques, including packaging the malware with VMProtect to make it difficult to reverse engineer and checking the graphics hardware on systems before deciding whether to actually execute the malicious payload as a way to suss out VMs. On Huntress' end, we used Claude to help wrangle with some of these analysis challenges during our investigation.

We reported the malicious Claude Artifact to Anthropic; as of publication on July 22, the public Claude Artifact had been removed.

Update: We have updated the malware attribution for this blog to SectopRAT due to the presence of HVNC in the .NET payload after closer inspection of the related Command and Control services revealed in the Ethereum BSC transactions.

Between July 21 and July 22, 2026, Huntress' Security Operations Center (SOC) lit up with a swathe of unusual executable installs, Defender exclusions, and anomalous persistence across 29 organizations, all coming from ClaudeDesktop.exe. The attacks had one common denominator: victims had searched for the Claude desktop app and were taken to a malicious public Claude Artifact on the actual Claude AI domain, which appeared to be a legitimate download link for the desktop app.

This is an extract. The publication continues at the source.

Read the original at the source: https://www.huntress.com/blog/fakeagent-claude-desktop-malvertising-ends-in-dotnet-rat

Officially imported this from Huntress’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

Provenance

Organization
Huntress — imported from official source
Official source
https://www.huntress.com/blog/rss.xml RSS
Imported
September 20, 2026 19:55
Versions
1 recorded
Identity
https://www.huntress.com/blog/fakeagent-claude-desktop-malvertising-ends-in-dotnet-rat

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.