Threat reportMalwareTL-2026-1669
FakeAgent Malvertising Campaign Distributes SectopRAT via Fake Claude Desktop Installer Hosted on claude.ai
FakeAgent Malvertising Campaign Distributes SectopRAT via (TL-2026-1669), also tracked as FakeAgent, is a high-severity malware campaign, first published 2026-07-24. It has no confirmed attribution, affects Anthropic Claude Desktop (fake/trojanized installer), maps to 27 MITRE ATT&CK techniques (T1005, T1008, T1027), and is covered by 9 detection rules and 34 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 27MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 34Indicators of compromise
Key facts for TL-2026-1669
- Threat ID
- TL-2026-1669
- Also known as
- FakeAgent
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- technology, professional-services, finance, general-enterprise
- Target regions
- North America, Europe, Global
- Detection rules
- 9
- Indicators of compromise
- 34
Malware and tooling in FakeAgent Malvertising Campaign Distributes SectopRAT via
Malware and tooling: Arechclient2, GhostSocks, SectopRAT, Stealc, Vidar, EtherHiding (BSC smart-contract C2 resolution), VMProtect
How FakeAgent Malvertising Campaign Distributes SectopRAT via works
Between July 21-22, 2026, a malvertising campaign used Bing sponsored search ads for "Claude Desktop App" to lure victims to a malicious Claude Artifact publicly hosted on the legitimate claude.ai domain, which redirected through attacker-controlled lookalike domains to a trojanized ClaudeDesktop.exe installer. The installer repackaged legitimate JetBrains and IBM SPSS binaries to abuse DLL sideloading, ultimately deploying SectopRAT (aka Arechclient2), a heavily obfuscated .NET remote access trojan with GPU-based anti-VM checks, shader-based payload decryption, VMProtect packing, and an Ethereum/BSC blockchain-based C2 resolution scheme (EtherHiding). Huntress identified the campaign after detecting anomalous installs and persistence across 29 affected organizations; the malicious artifact received 7,100 page views before Anthropic removed it.
FakeAgent is a malvertising and SEO-poisoning campaign that abused Anthropic's public Claude Artifact hosting feature on the legitimate claude.ai domain to distribute a trojanized "Claude Desktop" installer. Attackers purchased Bing sponsored search placements for queries such as "Claude Desktop App" and used SEO poisoning to surface a public Claude Artifact at claude[.]ai/public/artifacts/ca456f1f-44c0-42af-b329-4f1c7534a877, which functioned as a convincing fake download landing page hosted entirely on Anthropic's trusted domain -- defeating URL-reputation and domain-allowlist based defenses. Visitors clicking the download button were redirected off claude.ai through a two-hop attacker-controlled redirect chain (claude.ai.download-app[.]us -> downloading-api.it[.]com/html/claude/win) before being served a Windows executable named ClaudeDesktop.exe.
The delivered ClaudeDesktop.exe is in fact a renamed, legitimate, digitally-signed JetBrains helper binary (jcef_helper.exe) planted alongside a malicious libcef.dll in the same directory. Because the legitimate binary loads libcef.dll by name without full path validation or signature checks, Windows' standard DLL search order loads the attacker's malicious DLL instead of the real one -- classic DLL side-loading/hijack execution flow. The malicious libcef.dll is packed with VMProtect to hinder static and dynamic analysis and acts as a stager: it drops and schedules execution of a second sideloading pair -- a renamed IBM SPSS Statistics binary (sslconf.exe, masquerading as DockerDesktop.exe) paired with a malicious tempdir.dll -- establishing scheduled-task-based persistence.
tempdir.dll implements an unusual anti-analysis gate before decrypting and executing the final payload: it enumerates DXGI graphics adapters and inspects PCI vendor IDs to detect virtualized/emulated GPUs (QEMU 0x1234, VMware 0x15AD), checks allocated VRAM (rejecting environments reporting under 1GB), and performs shader execution timing checks to catch software GPU emulation used by malware sandboxes. Once the environment is judged to be a real physical host, the module decrypts the final payload (stored encrypted inside a companion appcfg.dat file) using a non-standard AES-256-CTR variant with a modified MixColumns step, with the decryption routine itself implemented as DirectX Shader Model 5 (SM5) bytecode executed on the GPU -- a technique that evades conventional CPU-side API hooking and EDR hooking of standard cryptographic APIs.
The decrypted final-stage payload is SectopRAT (also tracked as Arechclient2), an obfuscated .NET remote access trojan first seen circa 2019 and long associated with malvertising and fake-installer distribution. SectopRAT provides browser credential, cookie, autofill, and stored-card theft from Chromium-based browsers, FTP client credential theft, Discord and other messaging-app token theft, and a Hidden Virtual Network Computing (HVNC) module that lets an operator interact with a victim's desktop invisibly for live fraud and account-takeover operations. Uniquely for this campaign, SectopRAT resolves its command-and-control endpoint via EtherHiding: rather than a hardcoded C2 domain/IP, the malware queries Binance Smart Chain (BSC) smart contracts (0xe012d0f34cde9b870e9d9ed566ea5f8fd9b92228 for the SectopRAT payload and 0xc1907d7be91f95903ad66d775c397302e7dd9228 for the libcef.dll stager) whose on-chain transaction history stores encrypted, rotatable C2 network locations. This gives the operator low-cost, takedown-resistant C2 rotation -- historical transaction data on these contracts shows C2 addresses rotated from at least May 2025 (107.189.24.67) through July 2025 (104.194.133.210) up to the live campaign IP 2.24.131.246, plus a fallback UUID-style backup domain (5ca8758c-02d0-4a72-89c8-d468b66dda41[.]com).
Huntress observed the campaign across 29 distinct customer organizations, detecting it via anomalous new-install telemetry and unauthorized scheduled-task persistence rather than signature matching, and reported the malicious Claude Artifact to Anthropic, which removed it; the artifact had accumulated roughly 7,100 page views prior to takedown. Huntress also linked the same threat actor and libcef.dll sideloading technique to an April 2026 campaign distributing a fake Docker Desktop installer via Docker Hub, and to WHOIS infrastructure showing at least 10 domains registered under the same attacker identity extending back to December 2025, one of which (polse[.]us, previously used to host StealC stealer infrastructure) was seized by Microsoft during a prior Operation Endgame action. Huntress additionally noted concurrent, related malvertising activity distributing fake "OpenClaw" AI-tool installers carrying GhostSocks and Vidar infostealers, suggesting a broader actor or affiliate cluster abusing AI-tool brand recognition for malware distribution in mid-2026.
MITRE ATT&CK techniques used in TL-2026-1669
Collection
T1005 Data from Local System; T1560 Archive Collected Data
Command and Control
T1008 Fallback Channels; T1071 Application Layer Protocol; T1219 Remote Access Tools; T1568 Dynamic Resolution
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1070 Indicator Removal; T1140 Deobfuscate/Decode Files or Information; T1497 Virtualization/Sandbox Evasion; T1574 Hijack Execution Flow
Exfiltration
T1041 Exfiltration Over C2 Channel
Execution
T1053 Scheduled Task/Job; T1204 User Execution
Persistence
T1053 Scheduled Task/Job; T1547 Boot or Logon Autostart Execution
Privilege Escalation
Discovery
T1082 System Information Discovery; T1497 Virtualization/Sandbox Evasion; T1518 Software Discovery
Initial Access
T1189 Drive-by Compromise; T1566 Phishing
Credential Access
T1539 Steal Web Session Cookie; T1555 Credentials from Password Stores
stealth
Resource Development
T1583 Acquire Infrastructure; T1584 Compromise Infrastructure; T1608 Stage Capabilities
Impact
defense-impairment
Affected products and versions in FakeAgent Malvertising Campaign Distributes SectopRAT via
- Anthropic — Claude Desktop (fake/trojanized installer)
Vulnerable versions: N/A - impersonated product, no genuine vulnerable version
Fixed in: N/A - Microsoft — Windows (DLL side-loading abuse vector)
Vulnerable versions: Windows 10; Windows 11
Fixed in: N/A - abuse of default DLL search order behavior, not a patchable vulnerability - JetBrains — jcef_helper.exe (repackaged/abused as sideloading host)
Vulnerable versions: Any distributed copy vulnerable to libcef.dll side-loading
Fixed in: N/A - IBM — SPSS Statistics (sslconf.exe repackaged/abused as sideloading host)
Vulnerable versions: Any distributed copy vulnerable to tempdir.dll side-loading
Fixed in: N/A
Remediation for FakeAgent Malvertising Campaign Distributes SectopRAT via
Immediate actions
- Block outbound traffic to C2 IP 2.24.131.246 and backup domain 5ca8758c-02d0-4a72-89c8-d468b66dda41.com
- Block/sinkhole malvertising infrastructure domains claude.ai.download-app.us, download-app.us and downloading-api.it.com at DNS/web proxy
- Hunt for ClaudeDesktop.exe, DockerDesktop.exe and sslconf.exe processes not originating from official JetBrains or IBM SPSS installation paths
- Hunt for co-located libcef.dll and tempdir.dll files paired with renamed JetBrains/IBM SPSS executables outside their legitimate install directories
- Audit scheduled tasks created in the affected time window for unauthorized persistence entries
- Review Windows Defender exclusion lists for unauthorized additions
- Force credential resets (browser-stored, FTP, Discord, financial) for any host confirmed to have executed the trojanized installer
- Report and request takedown of any newly observed lookalike claude.ai Artifact download pages
Workarounds
- Disable or restrict execution of downloads originating from Bing/search-ad-driven traffic on managed endpoints pending verification
- Restrict public Claude Artifact links from being treated as trusted download sources by web/email security gateways
Longer-term hardening
- Deploy EDR rules that flag DLL side-loading pairs (signed launcher + unsigned/mismatched-signature sibling DLL)
- Implement application allowlisting so unsigned or unexpectedly-located executables cannot execute even when named after trusted software
- Monitor for anomalous DXGI/GPU enumeration API calls combined with shader compilation from non-graphics/non-gaming processes
- Monitor egress traffic to Binance Smart Chain / Ethereum JSON-RPC endpoints from endpoint processes as a potential EtherHiding C2 indicator
- User awareness training on verifying software downloads only via official vendor domains and not via sponsored search ads
- Establish a process with security vendors/partners for rapid reporting of abusive public Claude Artifacts to Anthropic Trust & Safety
Weaknesses (CWE) in FakeAgent Malvertising Campaign Distributes SectopRAT via
Timeline of FakeAgent Malvertising Campaign Distributes SectopRAT via
- Earliest observed C2 IP address (107.189.24.67) recorded in Binance Smart Chain smart-contract transaction history used for EtherHiding-based C2 resolution.
- C2 infrastructure rotates to 104.194.133.210 per subsequent BSC contract transaction, evidencing ongoing operational use of the same blockchain C2 scheme months before the Claude Desktop campaign.
- Attacker-linked WHOIS registration address begins registering a cluster of at least 10 lookalike/malvertising domains, per Validin indexing referenced by Huntress.
- Same threat actor distributes a fake Docker Desktop installer via Docker Hub using the identical libcef.dll DLL side-loading technique later reused in the Claude Desktop campaign.
- Malvertising domain download-app[.]us registered, later used as the first hop in the FakeAgent redirect chain.
- FakeAgent campaign is actively serving victims via Bing sponsored search ads directing to the malicious public Claude Artifact on claude.ai.
- Malpedia (Fraunhofer FKIE) publishes a library entry documenting the campaign and its SectopRAT/Arechclient2 attribution.
- Huntress reports the malicious Claude Artifact (claude[.]ai/public/artifacts/ca456f1f-44c0-42af-b329-4f1c7534a877, ~7,100 page views) to Anthropic; Anthropic removes the artifact.
- Huntress detects anomalous installs and unauthorized scheduled-task persistence across 29 customer organizations, identifies the malicious Claude Artifact and trojanized ClaudeDesktop.exe installer, and publishes technical analysis.
- Huntress blog post archived on the Wayback Machine, preserving the original technical disclosure.
Sources cited for FakeAgent Malvertising Campaign Distributes SectopRAT via
Detection coverage for TL-2026-1669
As of 2026-07-24, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1669 across Splunk SPL, Microsoft KQL and Sigma, covering 34 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.