DEV Community

Achin Bansal
Achin Bansal

Posted on • Originally published at gridthegrey.com

Fake Claude App via Bing Ads Delivers SectopRAT Malware

Forensic Summary

Attackers exploited Bing's ad platform and Anthropic's legitimate Claude.ai domain to distribute a fake Claude desktop installer laced with SectopRAT, a feature-rich remote access trojan with info-stealing and HVNC capabilities. The campaign, dubbed FakeAgent, compromised at least 29 organisations in a 48-hour window by abusing Claude Artifacts as a trusted hosting vector — a novel AI platform abuse technique. The incident highlights how threat actors are weaponising AI brand trust and legitimate AI infrastructure as malware delivery mechanisms.


Read the full technical deep-dive on Grid the Grey: https://gridthegrey.com/posts/fake-claude-app-via-bing-ads-delivers-sectoprat-malware/

Top comments (0)