> Back to All Posts

Fake Claude App Malware Hit 29 Firms via Bing Search Ads

Fake Claude App Malware

Downloading software feels simple. You search for the app, click the first result, and run the installer. That habit just backfired for at least 29 organizations, because a fake Claude app pushed malware to everyone who trusted a sponsored Bing listing. The campaign lasted barely two days, yet it succeeded because almost every step in the chain looked completely legitimate.

How the Fake Claude App Malware Campaign Worked

Attackers bought sponsored placements on Bing for searches tied to Claude downloads. Those ads appeared above the organic results, exactly where most people look first. Anyone who clicked landed on what looked like an official download portal. The browser bar even showed a claude.ai address.

Researchers at Huntress, who track the operation as FakeAgent, counted at least 29 compromised organizations between July 21 and July 22. The window was short, but the damage happened fast.

A phishing page hosted on a real domain

The trick relied on Claude Artifacts, a feature that lets users publish interactive pages on Anthropic’s own domain. Criminals built a fake download portal as an artifact, then let the platform host it for them. Visitors downloaded the file 7,100 times before Anthropic removed the page. Because the link pointed to a genuine service, the standard advice about checking the URL offered no protection.

The installer carried a hidden component

The portal served a file named ClaudeDesktop.exe. That executable was real software, a Chromium component built by JetBrains. Attackers paired it with a malicious DLL called libcef.dll, which the legitimate program loaded on launch. Security teams call this DLL sideloading, and it lets harmful code run under the cover of trusted software.

A second file, DockerDesktop.exe, created a scheduled task so the infection survived reboots. The loaders also packed heavy anti-analysis features, including VMProtect packing, virtual machine detection, and checks on GPU memory and shader timing. Those layers make automated sandboxes far less likely to catch the payload.

What SectopRAT Actually Steals

The final payload was SectopRAT, also tracked as ArechClient2. It has circulated since 2019 and works mainly as an information stealer. However, it adds a feature called HVNC, short for Hidden Virtual Network Computing. HVNC opens a hidden desktop session on the victim’s machine, so an attacker can click, type and browse in real time while the owner notices nothing.

The malware harvests a wide range of data:

  • Saved passwords and credit card details
  • Browser logins and cookies
  • Local files and FTP credentials
  • Chat data from Discord and Telegram
  • Steam account information
  • Credentials tied to VPN products

That final item deserves attention from privacy-focused readers.

Why VPN Users Should Care

A VPN protects data in transit. It hides your traffic from your internet provider and shields you on public Wi-Fi. Still, it cannot help once malware runs on the device itself. SectopRAT pulls credentials straight from local storage, long before any encryption applies.

Stolen VPN logins also create a second problem. An attacker can sign in, change the recovery email, and lock the real owner out of the account. Some resell working accounts on criminal markets instead. Providers that support two-factor authentication and display active session lists give you a fast way to spot that kind of takeover.

Command Servers Hidden on a Blockchain

SectopRAT locates its command server through a method known as EtherHiding. Operators write the current address into transactions on the BNB Smart Chain, and the malware simply reads it from there. Blockchain records cannot be deleted or seized, so defenders lose the takedown options that normally work against a domain or an IP address.

Investigators traced ten domains registered to a single email address since December 2025. Law enforcement had already seized one of them during Operation Endgame, after it appeared in earlier StealC distribution. Even so, nobody has linked FakeAgent to a known threat group with confidence.

There is one more detail worth noting. Analysts leaned on Claude Opus 4.8 during the investigation to help with shader emulation, cryptographic reconstruction and .NET code analysis. Criminals abused the brand as bait, while defenders used the product as a research tool.

How to Avoid the Next Fake Installer

A few habits remove most of the risk:

  • Skip sponsored results. Scroll past the ad block and use the vendor’s official site.
  • Bookmark the sources you use. Typing a known address beats searching every time.
  • Check the publisher before running an installer. A mismatched file name or signature is a red flag.
  • Treat trusted domains carefully. User-generated content can live on a legitimate URL, as this case proved.
  • Enable two-factor authentication. Stolen passwords lose most of their value when a second factor blocks the login.

Companies can go further by restricting software installation on employee machines. Endpoint detection tools also help, though the anti-analysis layers in this campaign show why detection alone rarely suffices.

Final Thoughts

The fake Claude app that delivered malware through Bing ads worked for one main reason: it borrowed credibility from real brands at every stage. A trusted search engine served the ad. A trusted domain hosted the lure. A trusted executable loaded the payload. Users had almost no visual cue that anything was wrong.

Attackers will keep targeting AI tool downloads because demand keeps rising and habits stay careless. Your best defence remains boring and effective. Go directly to the source, verify what you install, and protect the accounts that matter with a second factor. A VPN still guards your traffic, but only a clean device keeps your credentials yours.

Janet Andersen

Janet is an experienced content creator with a strong focus on cybersecurity and online privacy. With extensive experience in the field, she’s passionate about crafting in-depth reviews and guides that help readers make informed decisions about digital security tools. When she’s not managing the site, she loves staying on top of the latest trends in the digital world.