Fake Claude Desktop App Promoted via Bing Ads Delivers SectopRAT (ArechClient2) Malware

Fake Claude Desktop App Promoted via Bing Ads Delivers (TL-2026-1662), also tracked as FakeAgent, is a high-severity malware campaign, first published 2026-07-23. It has no confirmed attribution, affects Anthropic Claude Desktop app (brand impersonated), maps to 20 MITRE ATT&CK techniques (T1005, T1027, T1036), and is covered by 9 detection rules and 27 indicators of compromise.

Key facts for TL-2026-1662

Threat ID
TL-2026-1662
Also known as
FakeAgent
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
2026-07-23
Last reviewed
2026-07-23
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
unspecified - 29 organizations across multiple sectors
Target regions
Global
Detection rules
9
Indicators of compromise
27

Malware and tooling in Fake Claude Desktop App Promoted via Bing Ads Delivers

Malware and tooling: SectopRAT / ArechClient2, 0xc1907d7be91f95903ad66d775c397302e7dd9228, 0xe012d0f34cde9b870e9d9ed566ea5f8fd9b92228, VMProtect

A malvertising campaign dubbed 'FakeAgent' abused a public Claude Artifact hosted on Anthropic's legitimate claude.ai domain, surfaced via sponsored Bing search ads for 'Claude Desktop app', to redirect victims to a counterfeit ClaudeDesktop.exe installer. The installer repackages a legitimate JetBrains CEF helper (jcef_helper.exe) and sideloads a malicious libcef.dll to deploy SectopRAT (ArechClient2), an info-stealing RAT with HVNC capability that uses the EtherHiding technique to retrieve its C2 address from Ethereum/BNB Smart Chain transactions. The campaign ran July 21-22, 2026, generated 7,100 artifact page views/downloads, and compromised at least 29 organizations before removal.

How Fake Claude Desktop App Promoted via Bing Ads Delivers works

The FakeAgent campaign (disclosed by Huntress and reported by BleepingComputer on 2026-07-23) is a multi-stage malvertising and DLL-sideloading operation that specifically impersonates the Anthropic Claude brand to distribute the SectopRAT information stealer. Victims searching Bing for 'Claude Desktop app' were served a sponsored ad linking to a public Claude Artifact hosted directly on claude.ai (claude[.]ai/public/artifacts/ca456f1f-44c0-42af-b329-4f1c7534a877), lending the lure the legitimate domain's trust. The artifact redirected through claude.ai.download-app[.]us to downloading-api.it[.]com/html/claude/win, which served a trojanized ClaudeDesktop.exe.

Stage 1 (ClaudeDesktop.exe / DockerDesktop.exe) is a repackaged, VMProtect-packed copy of the legitimate JetBrains Chromium Embedded Framework helper (jcef_helper.exe) that sideloads a malicious libcef.dll. This stage resolves further instructions from an Ethereum BNB Smart Chain contract (0xc1907d7be91f95903ad66d775c397302e7dd9228) and downloads a secondary payload, cache.dat.

Stage 2 drops sslconf.exe (a repackaged IBM SPSS binary) to %APPDATA%\Roaming\Microsoft\EdgeUpdate\Install\sslconf.exe, masquerading as a Microsoft Edge update artifact, alongside a maliciously modified tempdir.dll it sideloads. This stage performs extensive anti-analysis: DXGI GPU adapter enumeration to detect QEMU (0x1234) and VMware (0x15AD) virtual GPU signatures, VRAM threshold checks (<1GB triggers evasion), and DirectX compute-shader timing checks to detect sandboxes/emulation.

Stage 3 decrypts an encrypted payload (appcfg.dat) using a custom AES-256-CTR variant with a modified MixColumns Row 3 transform, with the decryption routine executed as an SM5 DirectX shader on the GPU itself to frustrate static/dynamic analysis. Huntress used Claude Opus 4.8 to assist in reconstructing the shader's cryptographic logic and recovering S-boxes from the compiled DXBC bytecode.

Stage 4 is the final SectopRAT (ArechClient2) .NET payload — a heavily obfuscated info-stealer/RAT active since 2019 that harvests browser logins, cookies, autofill data, credit card numbers, Chromium master keys, FTP credentials, and Discord/Telegram/Steam/VPN client credentials, and provides HVNC (Hidden VNC) for interactive, invisible remote-hands-on access to the victim host. Its C2 channel resolves through a second BNB Smart Chain contract (0xe012d0f34cde9b870e9d9ed566ea5f8fd9b92228) using the EtherHiding technique, which stores C2 addressing data inside blockchain transactions so the operator can rotate infrastructure by broadcasting a new transaction rather than standing up a new server, resisting conventional domain/IP takedown.

Persistence is maintained via a scheduled task tied to DockerDesktop.exe for periodic reinfection and via the disguised sslconf.exe under the EdgeUpdate path. Huntress could not attribute the campaign to a known threat cluster but linked the domain-registration email to at least 10 other malicious domains registered since December 2025, one of which (polse[.]us) previously distributed the StealC stealer and was seized by Microsoft/Europol during Operation Endgame. The same libcef.dll DLL-sideloading technique was reportedly used in an April 2026 malicious Docker Hub campaign by what may be the same operator. SectopRAT has separately been observed via CastleLoader campaigns and ClickFix-style fake-CAPTCHA lures, indicating it is actively distributed through multiple malvertising/social-engineering channels in parallel with this campaign.

MITRE ATT&CK techniques used in TL-2026-1662

Collection

T1005 Data from Local System; T1560 Archive Collected Data

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1140 Deobfuscate/Decode Files or Information; T1497 Virtualization/Sandbox Evasion; T1574 Hijack Execution Flow

Exfiltration

T1041 Exfiltration Over C2 Channel

Persistence

T1053 Scheduled Task/Job

Command and Control

T1071 Application Layer Protocol; T1102 Web Service; T1568 Dynamic Resolution

Discovery

T1082 System Information Discovery; T1497 Virtualization/Sandbox Evasion

Initial Access

T1189 Drive-by Compromise

Execution

T1204 User Execution

Credential Access

T1539 Steal Web Session Cookie; T1555 Credentials from Password Stores

Resource Development

T1583 Acquire Infrastructure; T1588 Obtain Capabilities

Reconnaissance

T1593 Search Open Websites/Domains

Affected products and versions in Fake Claude Desktop App Promoted via Bing Ads Delivers

  • Anthropic — Claude Desktop app (brand impersonated)
    Vulnerable versions: N/A - counterfeit installer impersonates the legitimate product
    Fixed in: N/A
  • JetBrains — Chromium Embedded Framework helper (jcef_helper.exe / libcef.dll)
    Vulnerable versions: Legitimate binary abused as a DLL side-loading host
    Fixed in: N/A - vendor binary itself not vulnerable; abuse vector is unsigned DLL load order
  • Microsoft — Windows (all supported desktop versions)
    Vulnerable versions: Any Windows host where the user executes ClaudeDesktop.exe/DockerDesktop.exe
    Fixed in: N/A

Remediation for Fake Claude Desktop App Promoted via Bing Ads Delivers

Immediate actions

  • Block/remove the identified C2 domains and IPs at DNS and network perimeter (claude.ai.download-app[.]us, downloading-api.it[.]com, 5ca8758c-02d0-4a72-89c8-d468b66dda41[.]com, 2.24.131.246)
  • Hunt for the disclosed file hashes and filenames (ClaudeDesktop.exe, DockerDesktop.exe, sslconf.exe, libcef.dll, tempdir.dll, cache.dat, appcfg.dat) across endpoints
  • Search for the malicious scheduled task associated with DockerDesktop.exe and remove it
  • Inspect %APPDATA%\Roaming\Microsoft\EdgeUpdate\Install\ for unauthorized sslconf.exe
  • Force-rotate credentials/browser sessions on any host where the IOCs were found (browser passwords, cookies, Discord/Telegram/Steam/VPN/FTP credentials, stored payment cards)

Workarounds

  • Disable or restrict execution of publicly shared Claude Artifacts that request the user download and run an executable
  • Block search-ad-driven redirects to non-canonical claude.ai subdomains at the web proxy

Longer-term hardening

  • Deploy EDR with DLL side-loading and unsigned-DLL-load detection for trusted third-party executables (JetBrains CEF, IBM SPSS binaries)
  • Alert on outbound queries to Ethereum/BNB Smart Chain RPC endpoints from non-browser/non-wallet processes as a C2-channel indicator (EtherHiding)
  • Monitor for DXGI GPU adapter enumeration paired with DirectX compute shader execution in non-graphics-intensive processes
  • Restrict/monitor execution of software downloaded via sponsored search-engine ads; consider ad-blocking or DNS filtering for known malvertising redirector patterns
  • Educate users that legitimate Claude Desktop installers only come from anthropic.com/claude.ai official download pages, never from public Artifact links

Weaknesses (CWE) in Fake Claude Desktop App Promoted via Bing Ads Delivers

CWE-506, CWE-494, CWE-1021

Timeline of Fake Claude Desktop App Promoted via Bing Ads Delivers

  • Historical SectopRAT C2 IP 107.189.24.67 active, per Huntress infrastructure timeline linked to the same operator cluster
  • Historical SectopRAT C2 IP 104.194.133.210 active
  • Historical SectopRAT C2 IP 45.59.122.82 active
  • Operator begins registering the domain cluster (10+ domains under one registration email) later used in the FakeAgent campaign, including one (polse[.]us) later seized during Operation Endgame for StealC distribution
  • A related malvertising campaign abusing Docker Hub uses the same libcef.dll DLL side-loading technique, suggesting shared tooling/operator
  • Redirector domain claude.ai.download-app[.]us registered
  • Current SectopRAT C2 IP 2.24.131.246 becomes active
  • FakeAgent campaign begins: sponsored Bing ads for 'Claude Desktop app' begin redirecting to a malicious public Claude Artifact hosted on claude.ai
  • Campaign removed after generating 7,100 artifact page views/downloads and compromising at least 29 organizations
  • Huntress publishes technical analysis; BleepingComputer, IT Security Guru, and GBHackers report on the FakeAgent campaign

Sources cited for Fake Claude Desktop App Promoted via Bing Ads Delivers

Threats related to Fake Claude Desktop App Promoted via Bing Ads Delivers

Detection coverage for TL-2026-1662

As of 2026-07-23, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1662 across Splunk SPL, Microsoft KQL and Sigma, covering 27 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats