Inside FakeAgent: How a Claude Desktop Malvertising Campaign Hit 29 Organizations with SectopRAT

Huntress Version 1 original current

Imported from official source

On July 21 and July 22, Huntress observed a number of attacks that started with a malicious public Claude Artifact hosted on a legitimate Claude domain, and ended in organizations being infected by the SectopRAT stealer.

This version

Version
1 of 1
Recorded
September 20, 2026 19:55
Change
Initial
Content hash
9e10b83f69d6a0ea2b950f934e84460c
All versions
Revision history

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.