Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Inside FakeAgent: How a Claude Desktop Malvertising Campaign Hit 29 Organizations with SectopRAT

0
Medium
Published: 07/23/2026 (07/23/2026, 00:27:48 UTC)
Source: AlienVault OTX General

Description

Between July 21-22, 2026, 29 organizations were compromised through a sophisticated malvertising campaign exploiting Claude AI's legitimate domain. Victims searching for Claude Desktop via Bing encountered sponsored advertisements leading to a malicious Claude Artifact hosted on the authentic Claude.ai domain. This artifact redirected users to attacker-controlled infrastructure distributing a fake ClaudeDesktop.exe file containing SectopRAT. The malware employed advanced anti-analysis techniques including VMProtect packing, GPU-based virtual machine detection, and DirectX shader-based payload decryption. Command-and-control infrastructure utilized EtherHiding, storing C2 addresses in Ethereum blockchain transactions for resilience against takedowns. The remote access trojan exfiltrated credit card data, credentials, browser information, and personal files. Analysis revealed connections to previous campaigns dating to December 2025, with infrastructure linked to Operation Endgame seizures and StealC distrib...

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/23/2026, 16:00:04 UTC

Technical Analysis

This threat involves a sophisticated malvertising campaign leveraging the legitimate Claude.ai domain to distribute a fake ClaudeDesktop.exe malware implant named SectopRAT. Victims searching for Claude Desktop via Bing ads were redirected to malicious infrastructure hosting the fake executable. SectopRAT employs multiple advanced evasion techniques including VMProtect packing, GPU-based virtual machine detection, and DirectX shader-based payload decryption to hinder analysis. The malware's command-and-control infrastructure uses EtherHiding, storing C2 addresses within Ethereum blockchain transactions to increase resilience against takedown efforts. SectopRAT exfiltrates sensitive data such as credit card details, credentials, browser information, and personal files. The campaign impacted 29 organizations and is connected to previous malicious activity dating to December 2025, with infrastructure linked to known operations such as Operation Endgame and StealC distribution.

Potential Impact

The malware exfiltrates sensitive information including credit card data, user credentials, browser data, and personal files, potentially leading to financial loss, identity theft, and further network compromise. The use of advanced anti-analysis and evasion techniques complicates detection and response. The resilient command-and-control infrastructure leveraging the Ethereum blockchain makes disruption and takedown more difficult, prolonging attacker control and data exfiltration capabilities.

Mitigation Recommendations

No official patch or remediation is available as this is a malware campaign leveraging social engineering and malvertising rather than a software vulnerability. Defenders should educate users to avoid downloading software from unofficial sources or ads, verify software authenticity, and employ endpoint detection solutions capable of identifying SectopRAT and its evasion techniques. Network monitoring for suspicious connections to Ethereum blockchain transactions or known C2 infrastructure may assist detection. Since this is not a cloud service, remediation depends on organizational security controls and user awareness.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.huntress.com/blog/fakeagent-claude-desktop-malvertising-ends-in-dotnet-rat"]
Adversary
null
Pulse Id
6a616004250472ee87e19829
Threat Score
null

Indicators of Compromise

Ip

ValueDescriptionCopy
ip104.194.133.210
CC=US ASN=AS53667 frantech solutions
ip107.189.24.67
CC=US ASN=AS53667 frantech solutions
ip107.189.26.86
CC=US ASN=AS53667 frantech solutions
ip107.189.21.86
CC=US ASN=AS53667 frantech solutions
ip45.59.124.17
CC=US ASN=AS46261 quickpacket llc
ip107.189.17.143
CC=US ASN=AS53667 frantech solutions
ip45.59.125.228
CC=US ASN=AS46261 quickpacket llc
ip45.59.122.134
CC=US ASN=AS46261 quickpacket llc
ip45.59.122.235
CC=US ASN=AS46261 quickpacket llc
ip107.189.22.118
CC=US ASN=AS53667 frantech solutions
ip107.189.20.32
CC=US ASN=AS53667 frantech solutions
ip107.189.20.95
CC=US ASN=AS53667 frantech solutions
ip45.59.117.145
CC=US ASN=AS46261 quickpacket llc
ip45.59.114.190
CC=US ASN=AS46261 quickpacket llc
ip45.59.123.122
CC=US ASN=AS46261 quickpacket llc
ip45.59.117.67
CC=US ASN=AS46261 quickpacket llc
ip191.101.80.211
CC=AE ASN=AS61317 digital energy technologies ltd.
ip2.24.131.246
CC=GB ASN=AS12576 ee limited
ip195.110.58.222
CC=GB ASN=AS47583 hostinger international limited

Url

ValueDescriptionCopy
urlhttp://107.189.24.255

Domain

ValueDescriptionCopy
domaindownload-app.us
domain5ca8758c-02d0-4a72-89c8-d468b66dda41.com
domainclaude.ai.download-app.us

Hash

ValueDescriptionCopy
hash04dcc1abb68aae9d3ae4901cc140dbb8
hash71fdd6fb7f0acd3e9a6206851452e11b
hash82011a9ff3692236df69427eb200ba05799205b0
hashda7a5028b9694c406a881eb85e5acd8ea375a890
hash1cd58cfba596da296ab1878d74023e00c399345a1b6c2a0e5446c53563f4e3bb
hash1fe3646d27d286db8123297e06ae7badf3e26f352a04f91b6d82c28869a91664
hash26bae4d7012bf59847ab4036a065419c3d4ca47e020479f55b3b2c6d0d21394a
hashf8acb8f5cf88b77a4c27d7fd6856aa299bb178e85f9963c2fbd447d818da3ed0
hashfd826215add30c1319eefa291b6eaf8ddfa7720cfe816c49aef6fe8a88de7939

Threat ID: 6a6231af9c2644c7f847147d

Added to database: 07/23/2026, 15:22:23 UTC

Last enriched: 07/23/2026, 16:00:04 UTC

Last updated: 07/23/2026, 20:52:02 UTC

Views: 25

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses