DEV Community

Achin Bansal
Achin Bansal

Posted on Originally published at gridthegrey.com

Fake Claude App via Bing Ads Delivers SectopRAT Malware

Forensic Summary

Attackers exploited Bing's ad platform and Anthropic's legitimate Claude.ai domain to distribute a fake Claude desktop installer laced with SectopRAT, a feature-rich remote access trojan with info-stealing and HVNC capabilities. The campaign, dubbed FakeAgent, compromised at least 29 organisations in a 48-hour window by abusing Claude Artifacts as a trusted hosting vector — a novel AI platform abuse technique. The incident highlights how threat actors are weaponising AI brand trust and legitimate AI infrastructure as malware delivery mechanisms.


Read the full technical deep-dive on Grid the Grey: https://gridthegrey.com/posts/fake-claude-app-via-bing-ads-delivers-sectoprat-malware/

Top comments (0)