# FakeAgent Malvertising Campaign Distributes SectopRAT via Fake Claude Desktop Installer Hosted on claude.ai

> Between July 21-22, 2026, a malvertising campaign used Bing sponsored search ads for "Claude Desktop App" to lure victims to a malicious Claude Artifact publicly hosted on the legitimate claude.ai domain, which redirected through attacker-controlled lookalike domains to a trojanized ClaudeDesktop.exe installer. The installer repackaged legitimate JetBrains and IBM SPSS binaries to abuse DLL sideloading, ultimately deploying SectopRAT (aka Arechclient2), a heavily obfuscated .NET remote access trojan with GPU-based anti-VM checks, shader-based payload decryption, VMProtect packing, and an Ethereum/BSC blockchain-based C2 resolution scheme (EtherHiding). Huntress identified the campaign after detecting anomalous installs and persistence across 29 affected organizations; the malicious artifact received 7,100 page views before Anthropic removed it.

- **Published:** 2026-07-24T00:00:00Z
- **Last reviewed:** 2026-07-24T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1669
- **ID:** TL-2026-1669
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 34 (full data via the Threadlinqs MCP server — Purple tier)

## Description

FakeAgent is a malvertising and SEO-poisoning campaign that abused Anthropic's public Claude Artifact hosting feature on the legitimate claude.ai domain to distribute a trojanized "Claude Desktop" installer. Attackers purchased Bing sponsored search placements for queries such as "Claude Desktop App" and used SEO poisoning to surface a public Claude Artifact at claude[.]ai/public/artifacts/ca456f1f-44c0-42af-b329-4f1c7534a877, which functioned as a convincing fake download landing page hosted entirely on Anthropic's trusted domain -- defeating URL-reputation and domain-allowlist based defenses. Visitors clicking the download button were redirected off claude.ai through a two-hop attacker-controlled redirect chain (claude.ai.download-app[.]us -> downloading-api.it[.]com/html/claude/win) before being served a Windows executable named ClaudeDesktop.exe.

The delivered ClaudeDesktop.exe is in fact a renamed, legitimate, digitally-signed JetBrains helper binary (jcef_helper.exe) planted alongside a malicious libcef.dll in the same directory. Because the legitimate binary loads libcef.dll by name without full path validation or signature checks, Windows' standard DLL search order loads the attacker's malicious DLL instead of the real one -- classic DLL side-loading/hijack execution flow. The malicious libcef.dll is packed with VMProtect to hinder static and dynamic analysis and acts as a stager: it drops and schedules execution of a second sideloading pair -- a renamed IBM SPSS Statistics binary (sslconf.exe, masquerading as DockerDesktop.exe) paired with a malicious tempdir.dll -- establishing scheduled-task-based persistence.

tempdir.dll implements an unusual anti-analysis gate before decrypting and executing the final payload: it enumerates DXGI graphics adapters and inspects PCI vendor IDs to detect virtualized/emulated GPUs (QEMU 0x1234, VMware 0x15AD), checks allocated VRAM (rejecting environments reporting under 1GB), and performs shader execution timing checks to catch software GPU emulation used by malware sandboxes. Once the environment is judged to be a real physical host, the module decrypts the final payload (stored encrypted inside a companion appcfg.dat file) using a non-standard AES-256-CTR variant with a modified MixColumns step, with the decryption routine itself implemented as DirectX Shader Model 5 (SM5) bytecode executed on the GPU -- a technique that evades conventional CPU-side API hooking and EDR hooking of standard cryptographic APIs.

The decrypted final-stage payload is SectopRAT (also tracked as Arechclient2), an obfuscated .NET remote access trojan first seen circa 2019 and long associated with malvertising and fake-installer distribution. SectopRAT provides browser credential, cookie, autofill, and stored-card theft from Chromium-based browsers, FTP client credential theft, Discord and other messaging-app token theft, and a Hidden Virtual Network Computing (HVNC) module that lets an operator interact with a victim's desktop invisibly for live fraud and account-takeover operations. Uniquely for this campaign, SectopRAT resolves its command-and-control endpoint via EtherHiding: rather than a hardcoded C2 domain/IP, the malware queries Binance Smart Chain (BSC) smart contracts (0xe012d0f34cde9b870e9d9ed566ea5f8fd9b92228 for the SectopRAT payload and 0xc1907d7be91f95903ad66d775c397302e7dd9228 for the libcef.dll stager) whose on-chain transaction history stores encrypted, rotatable C2 network locations. This gives the operator low-cost, takedown-resistant C2 rotation -- historical transaction data on these contracts shows C2 addresses rotated from at least May 2025 (107.189.24.67) through July 2025 (104.194.133.210) up to the live campaign IP 2.24.131.246, plus a fallback UUID-style backup domain (5ca8758c-02d0-4a72-89c8-d468b66dda41[.]com).

Huntress observed the campaign across 29 distinct customer organizations, detecting it via anomalous new-install telemetry and unauthorized scheduled-task persistence rather than signature matching, and reported the malicious Claude Artifact to Anthropic, which removed it; the artifact had accumulated roughly 7,100 page views prior to takedown. Huntress also linked the same threat actor and libcef.dll sideloading technique to an April 2026 campaign distributing a fake Docker Desktop installer via Docker Hub, and to WHOIS infrastructure showing at least 10 domains registered under the same attacker identity extending back to December 2025, one of which (polse[.]us, previously used to host StealC stealer infrastructure) was seized by Microsoft during a prior Operation Endgame action. Huntress additionally noted concurrent, related malvertising activity distributing fake "OpenClaw" AI-tool installers carrying GhostSocks and Vidar infostealers, suggesting a broader actor or affiliate cluster abusing AI-tool brand recognition for malware distribution in mid-2026.

## MITRE ATT&CK

- T1583 Acquire Infrastructure
- T1584 Compromise Infrastructure
- T1608 Stage Capabilities
- T1566 Phishing
- T1189 Drive-by Compromise
- T1204 User Execution
- T1053 Scheduled Task/Job
- T1053 Scheduled Task/Job
- T1547 Boot or Logon Autostart Execution
- T1574 Hijack Execution Flow
- T1053 Scheduled Task/Job
- T1574 Hijack Execution Flow
- T1036 Masquerading
- T1027 Obfuscated Files or Information
- T1140 Deobfuscate/Decode Files or Information
- T1497 Virtualization/Sandbox Evasion
- T1685 Disable or Modify Tools
- T1070 Indicator Removal
- T1555 Credentials from Password Stores
- T1539 Steal Web Session Cookie
- T1497 Virtualization/Sandbox Evasion
- T1518 Software Discovery
- T1082 System Information Discovery
- T1005 Data from Local System
- T1560 Archive Collected Data
- T1071 Application Layer Protocol
- T1568 Dynamic Resolution
- T1219 Remote Access Tools
- T1008 Fallback Channels
- T1041 Exfiltration Over C2 Channel
- T1657 Financial Theft

## Sources

- [Inside FakeAgent: How a Claude Desktop Malvertising Campaign Hit 29 Organizations with SectopRAT](https://www.huntress.com/blog/fakeagent-claude-desktop-malvertising-ends-in-dotnet-rat)
- [FakeAgent Claude Desktop Malvertising campaign - Malpedia library entry](https://malpedia.caad.fkie.fraunhofer.de/library/e557c4f6-4711-4e3b-b09e-096db29e9091/)
- [Huntress Blog Archive Snapshot - FakeAgent Campaign](https://web.archive.org/web/2026/https://www.huntress.com/blog/fakeagent-claude-desktop-malvertising-ends-in-dotnet-rat)
- [Malpedia win.sectop_rat family entry](https://malpedia.caad.fkie.fraunhofer.de/details/win.sectop_rat)
- [Anthropic Claude Artifacts documentation](https://www.anthropic.com/news/artifacts)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1669
