HomeCyber BalkansFakeAgent Campaign Utilizes Malicious Claude Artifact to Distribute SectopRAT to 29 Organizations

FakeAgent Campaign Utilizes Malicious Claude Artifact to Distribute SectopRAT to 29 Organizations

Published on

spot_img

Malvertising Campaign Exploits Anthropic’s Claude.ai to Distribute SectopRAT Trojan

Researchers at Huntress recently uncovered a sophisticated malvertising campaign that targeted users seeking the Claude Desktop application on the internet. Dubbed "FakeAgent," the initiative launched between July 21 and 22, 2026, and successfully compromised at least 29 organizations within a mere 48-hour window.

The campaign operated by utilizing a sponsored advertisement that appeared in Bing search results when users searched for "Claude Desktop app." Unlike surrounding malicious ads, this particular advertisement linked directly to the legitimate claude.ai domain. However, upon clicking the ad, unsuspecting users were not redirected to Anthropic’s official download page. Instead, they were taken to a public Claude Artifact, which is a user-generated content feature that Anthropic allows its users to host and share. This spoofed artifact was designed to mimic the official Claude Desktop installer, thereby luring victims into a deceptive trap.

Once victims clicked on the fake "Download" button, they were redirected through a series of attacker-controlled domains, notably including claude.ai.download-app[.]us. This chain of redirection eventually led to the delivery of a malicious file named ClaudeDesktop.exe. It is important to note that Huntress promptly reported the malicious artifact to Anthropic, which removed the exposure on July 22, but not before the compromised page had attracted over 7,100 views.

Sophisticated Malware Tactics

The technical analysis conducted by Huntress illuminated the complexity of the attack. The malicious executable did not contain the genuine Claude Desktop installer; rather, it was a modified JetBrains binary (jcef_helper.exe) that was vulnerable to DLL sideloading. The true malicious payload was concealed within a tampered libcef.dll file, which was protected using the commercial software VMProtect, making reverse engineering significantly more difficult.

The second stage of the attack was delivered through a legitimate but compromised IBM SPSS binary, along with a malicious tempdir.dll. This segment of the payload executed a GPU-based anti-analysis check that specifically targeted DirectX graphics adapters for signatures that indicated the presence of virtual machines, such as those used by QEMU and VMware. This technique measured shader execution timing to determine whether to execute the malicious payload.

In a particularly notable twist, the core malware used a custom DirectX shader to decrypt its payload rather than relying on standard CPU routines. Huntress emphasized that this method presents a significant challenge to traditional reverse-engineering tools. Researchers utilized Claude Opus 4.8 to help reconstruct an SM5 bytecode interpreter to recover the AES-256-CTR key material embedded within the shader. Ultimately, this investigative work identified the malware as SectopRAT, a remote access trojan engineered to exfiltrate sensitive information, including browser credentials, autofill data, payment card details, and files.

Concealment through Blockchain

In a shrewd move, the command-and-control infrastructure used by the operators of SectopRAT was cleverly hidden within Ethereum blockchain transactions, a technique known as "EtherHiding." This strategy allows attackers to rotate their infrastructure seamlessly by posting new transactions rather than relying on servers that may be subject to takedowns by law enforcement or cybersecurity entities.

Historical Context and Attribution

Huntress’s investigation utilized WHOIS lookups and threat-intelligence reports from Validin to link the registration email associated with the campaign’s infrastructure to at least ten other domains. These domains date back to December 2025, including one that was seized by Microsoft during Operation Endgame for its involvement in hosting the StealC information-stealing trojan. Additionally, the operators were tied to an earlier campaign from April 2026 that distributed a similarly themed fake Docker Desktop installer via Docker Hub.

The analysis of Ethereum-based command-and-control transactions traced the operator activity back to May 2025, revealing a longstanding pattern of malicious behavior.

Industry Implications

This disturbing incident highlights a troubling trend in which attackers are increasingly targeting AI platforms directly, rather than relying solely on traditional methods like typosquatting. Huntress pointed out that this is not an isolated incident, referencing earlier reports about similar fake Claude download campaigns.

Huntress has urged users to approach search-engine advertisements with caution, even when the domains appear legitimate. "Do not trust top-level domains implicitly," they warned, stressing the importance of vigilance in the face of SEO poisoning and malvertising tactics as prevalent vectors for initial access in cybersecurity breaches.

For those interested in a deeper technical dive, the full analysis, including indicators of compromise and a rundown of historically relevant command-and-control IP addresses extracted from the blockchain transactions, can be found on the Huntress blog at Huntress Blog.

The reporting of this significant cybersecurity concern serves as a stark reminder for organizations and individuals to remain vigilant and informed in an increasingly complex threat landscape.

Source link

Latest articles

Iranian Hackers Attack Siemens and Schneider Industrial Systems

Iranian Cyber Campaign Targets US Critical Infrastructure Recent reports highlight a concerning trend involving Iranian...

CISA Issues New Warning About Exposed PLCs

Internet-Exposed Programmable Logic Controllers Present an Easy Target for Hackers In a troubling revelation this...

Security Teams Transition from AI-Only to Hybrid Penetration Testing

Shift from Full AI Automation in Penetration Testing: A Return to Human Expertise In a...

Check Point Vulnerability Allows Unauthenticated Attackers to Access Full SmartConsole Admin Privileges

Challenges of IP Address Restrictions in Cybersecurity In today's increasingly digital landscape, cybersecurity remains a...

More like this

Iranian Hackers Attack Siemens and Schneider Industrial Systems

Iranian Cyber Campaign Targets US Critical Infrastructure Recent reports highlight a concerning trend involving Iranian...

CISA Issues New Warning About Exposed PLCs

Internet-Exposed Programmable Logic Controllers Present an Easy Target for Hackers In a troubling revelation this...

Security Teams Transition from AI-Only to Hybrid Penetration Testing

Shift from Full AI Automation in Penetration Testing: A Return to Human Expertise In a...