Affected Systems
Organizations searching for Claude AI desktop app via Bing. Malicious Claude Artifact (downloaded 7,100 times) hosted on legitimate claude.ai domain redirected users to fake ClaudeDesktop.exe installer. At least 29 organizations compromised July 21-22, 2026. SectopRAT targets credentials, browser data, FTP, messaging clients (Discord, Telegram), Steam, and VPN products.
Exploitation Status
Active exploitation confirmed. Campaign named FakeAgent compromised at least 29 organizations between July 21-22, 2026. Malicious artifact was downloaded 7,100 times before removal by Anthropic. SectopRAT malware (active since 2019) uses DLL sideloading via legitimate JetBrains component, features anti-analysis protections (VMProtect, VM detection, shader timing checks), and retrieves C2 via Ethereum BNB Smart Chain (EtherHiding technique).
Business Impact
High-impact credential theft and remote access campaign exploiting trusted brand and legitimate domain infrastructure. SectopRAT provides attackers with HVNC (Hidden Virtual Network Computing) for real-time hands-on-keyboard access to compromised systems. Targets passwords, credit cards, browser sessions, FTP credentials, and data from Discord, Telegram, Steam, and VPN clients. Anti-analysis features may evade sandbox detection. Persistence via scheduled task (DockerDesktop.exe). Attribution unclear but infrastructure linked to StealC distribution and Operation Endgame seizures.
Urgency
🔴 Immediate
Recommended Actions
- Block execution of ClaudeDesktop.exe and DockerDesktop.exe via EDR/application control policies; hunt for JetBrains chrome_elf.exe with suspicious libcef.dll sideloading in environment
- Search scheduled tasks for DockerDesktop.exe persistence mechanism; review task scheduler logs for unauthorized entries created July 21-22, 2026
- Monitor outbound connections to Ethereum BNB Smart Chain nodes and unusual blockchain transaction queries (EtherHiding C2 retrieval behavior)
- Review Bing search ad click telemetry and web proxy logs for visits to claude.ai Artifact pages and subsequent downloads of ClaudeDesktop.exe
- Enforce policy to download software only from official vendor sites; block Bing sponsored search results for high-risk software categories via web filtering
- Reset credentials and revoke sessions for users who downloaded ClaudeDesktop.exe; scan for exfiltration of browser cookies, FTP credentials, and messaging app data
