Inside FakeAgent: How a Claude Desktop Malvertising Campaign Hit 29 Organizations with SectopRAT
Between July 21-22, 2026, 29 organizations were compromised through a sophisticated malvertising campaign exploiting Claude AI's legitimate domain. Victims searching for Claude Desktop via Bing encountered sponsored advertisements leading to a malicious Claude Artifact hosted on the authentic Claude.ai domain. This artifact redirected users to attacker-controlled infrastructure distributing a fake ClaudeDesktop.exe file containing SectopRAT. The malware employed advanced anti-analysis techniques including VMProtect packing, GPU-based virtual machine detection, and DirectX shader-based payload decryption. Command-and-control infrastructure utilized EtherHiding, storing C2 addresses in Ethereum blockchain transactions for resilience against takedowns. The remote access trojan exfiltrated credit card data, credentials, browser information, and personal files. Analysis revealed connections to previous campaigns dating to December 2025, with infrastructure linked to Operation Endgame seizures and StealC distrib...
Indicators of Compromise
- ip: 104.194.133.210
- ip: 107.189.24.67
- ip: 107.189.26.86
- ip: 107.189.21.86
- ip: 45.59.124.17
- ip: 107.189.17.143
- ip: 45.59.125.228
- ip: 45.59.122.134
- ip: 45.59.122.235
- ip: 107.189.22.118
- ip: 107.189.20.32
- ip: 107.189.20.95
- url: http://107.189.24.255
- ip: 45.59.117.145
- ip: 45.59.114.190
- ip: 45.59.123.122
- ip: 45.59.117.67
- domain: download-app.us
- ip: 191.101.80.211
- ip: 2.24.131.246
- hash: 04dcc1abb68aae9d3ae4901cc140dbb8
- hash: 71fdd6fb7f0acd3e9a6206851452e11b
- hash: 82011a9ff3692236df69427eb200ba05799205b0
- hash: da7a5028b9694c406a881eb85e5acd8ea375a890
- hash: 1cd58cfba596da296ab1878d74023e00c399345a1b6c2a0e5446c53563f4e3bb
- hash: 1fe3646d27d286db8123297e06ae7badf3e26f352a04f91b6d82c28869a91664
- hash: 26bae4d7012bf59847ab4036a065419c3d4ca47e020479f55b3b2c6d0d21394a
- hash: f8acb8f5cf88b77a4c27d7fd6856aa299bb178e85f9963c2fbd447d818da3ed0
- hash: fd826215add30c1319eefa291b6eaf8ddfa7720cfe816c49aef6fe8a88de7939
- domain: 5ca8758c-02d0-4a72-89c8-d468b66dda41.com
- domain: claude.ai.download-app.us
- ip: 195.110.58.222
Inside FakeAgent: How a Claude Desktop Malvertising Campaign Hit 29 Organizations with SectopRAT
Description
Between July 21-22, 2026, 29 organizations were compromised through a sophisticated malvertising campaign exploiting Claude AI's legitimate domain. Victims searching for Claude Desktop via Bing encountered sponsored advertisements leading to a malicious Claude Artifact hosted on the authentic Claude.ai domain. This artifact redirected users to attacker-controlled infrastructure distributing a fake ClaudeDesktop.exe file containing SectopRAT. The malware employed advanced anti-analysis techniques including VMProtect packing, GPU-based virtual machine detection, and DirectX shader-based payload decryption. Command-and-control infrastructure utilized EtherHiding, storing C2 addresses in Ethereum blockchain transactions for resilience against takedowns. The remote access trojan exfiltrated credit card data, credentials, browser information, and personal files. Analysis revealed connections to previous campaigns dating to December 2025, with infrastructure linked to Operation Endgame seizures and StealC distrib...
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.huntress.com/blog/fakeagent-claude-desktop-malvertising-ends-in-dotnet-rat"]
- Adversary
- null
- Pulse Id
- 6a616004250472ee87e19829
- Threat Score
- null
Indicators of Compromise
Ip
| Value | Description | Copy |
|---|---|---|
ip104.194.133.210 | CC=US ASN=AS53667 frantech solutions | |
ip107.189.24.67 | CC=US ASN=AS53667 frantech solutions | |
ip107.189.26.86 | CC=US ASN=AS53667 frantech solutions | |
ip107.189.21.86 | CC=US ASN=AS53667 frantech solutions | |
ip45.59.124.17 | CC=US ASN=AS46261 quickpacket llc | |
ip107.189.17.143 | CC=US ASN=AS53667 frantech solutions | |
ip45.59.125.228 | CC=US ASN=AS46261 quickpacket llc | |
ip45.59.122.134 | CC=US ASN=AS46261 quickpacket llc | |
ip45.59.122.235 | CC=US ASN=AS46261 quickpacket llc | |
ip107.189.22.118 | CC=US ASN=AS53667 frantech solutions | |
ip107.189.20.32 | CC=US ASN=AS53667 frantech solutions | |
ip107.189.20.95 | CC=US ASN=AS53667 frantech solutions | |
ip45.59.117.145 | CC=US ASN=AS46261 quickpacket llc | |
ip45.59.114.190 | CC=US ASN=AS46261 quickpacket llc | |
ip45.59.123.122 | CC=US ASN=AS46261 quickpacket llc | |
ip45.59.117.67 | CC=US ASN=AS46261 quickpacket llc | |
ip191.101.80.211 | CC=AE ASN=AS61317 digital energy technologies ltd. | |
ip2.24.131.246 | CC=GB ASN=AS12576 ee limited | |
ip195.110.58.222 | CC=GB ASN=AS47583 hostinger international limited |
Url
| Value | Description | Copy |
|---|---|---|
urlhttp://107.189.24.255 | — |
Domain
| Value | Description | Copy |
|---|---|---|
domaindownload-app.us | — | |
domain5ca8758c-02d0-4a72-89c8-d468b66dda41.com | — | |
domainclaude.ai.download-app.us | — |
Hash
| Value | Description | Copy |
|---|---|---|
hash04dcc1abb68aae9d3ae4901cc140dbb8 | — | |
hash71fdd6fb7f0acd3e9a6206851452e11b | — | |
hash82011a9ff3692236df69427eb200ba05799205b0 | — | |
hashda7a5028b9694c406a881eb85e5acd8ea375a890 | — | |
hash1cd58cfba596da296ab1878d74023e00c399345a1b6c2a0e5446c53563f4e3bb | — | |
hash1fe3646d27d286db8123297e06ae7badf3e26f352a04f91b6d82c28869a91664 | — | |
hash26bae4d7012bf59847ab4036a065419c3d4ca47e020479f55b3b2c6d0d21394a | — | |
hashf8acb8f5cf88b77a4c27d7fd6856aa299bb178e85f9963c2fbd447d818da3ed0 | — | |
hashfd826215add30c1319eefa291b6eaf8ddfa7720cfe816c49aef6fe8a88de7939 | — |
Threat ID: 6a6231af9c2644c7f847147d
Added to database: 07/23/2026, 15:22:23 UTC
Last enriched: 08/23/2026, 10:53:19 UTC
Last updated: 09/05/2026, 05:18:18 UTC
Views: 269
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.