Ten Minutes to Containment: How Agentic MXDR Scoped a Fake Claude Desktop Intrusion
Description
A masqueraded scheduled task alert triggered an aggressive threat hunt that uncovered a complete FakeAgent intrusion campaign within ten minutes using an automated threat hunting agent. The campaign leveraged malvertising on Bing to distribute trojanized Claude Desktop installers hosted on legitimate Anthropic infrastructure. The attack chain featured DLL sideloading via Java Chromium Embedded Framework, Microsoft Defender tampering, scheduled task persistence masquerading as Microsoft Edge updates, and blockchain-based command-and-control infrastructure using EtherHiding techniques. The hunting agent executed correlated queries across multiple kill chain phases simultaneously, providing confidence-scored findings that enabled rapid validation and remediation. The intrusion delivered SectopRAT malware with infostealing and remote desktop capabilities, requiring full endpoint reimaging and credential resets.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This campaign leveraged malvertising on Bing to distribute trojanized Claude Desktop installers hosted on legitimate Anthropic infrastructure. The attack chain included DLL sideloading via Java Chromium Embedded Framework, Microsoft Defender tampering, and scheduled task persistence disguised as Microsoft Edge updates. Command-and-control infrastructure used blockchain-based EtherHiding techniques. An automated threat hunting agent correlated queries across multiple kill chain phases, enabling rapid detection and containment within ten minutes. The intrusion delivered SectopRAT malware capable of infostealing and remote desktop access, requiring full endpoint reimaging and credential resets to remediate.
Potential Impact
The intrusion results in deployment of SectopRAT malware, which compromises endpoint security by stealing information and providing remote desktop access to attackers. The attack chain's tampering with Microsoft Defender and use of scheduled task persistence disguised as legitimate updates complicates detection and removal. Affected systems require full reimaging and credential resets to fully remediate the compromise.
Defensive Guidance
No official patch or fix is available for this campaign as it is an active malware intrusion rather than a software vulnerability. Mitigation relies on rapid detection and response capabilities, including automated threat hunting agents that correlate multiple kill chain phases and provide confidence-scored findings for quick validation. Organizations should monitor for indicators such as the domain neeitoerw.my and IP 153.75.84.173, and be vigilant for scheduled tasks masquerading as Microsoft Edge updates. Full endpoint reimaging and credential resets are necessary to remediate infected systems.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.cyberproof.com/blog/ten-minutes-to-containment-how-agentic-mxdr-scoped-a-fake-claude-desktop-intrusion/"]
- Pulse Id
- 6a8cb55752ef1f23f4813908
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domainneeitoerw.my | — |
Ip
| Value | Description | Copy |
|---|---|---|
ip153.75.84.173 | — |
Threat ID: 6a8ee500acd9273b49e81b8b
Added to database: 08/26/2026, 13:07:12 UTC
Last enriched: 09/24/2026, 01:47:43 UTC
Last updated: 10/03/2026, 16:19:48 UTC
Views: 76
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.