A dangerous new malware campaign is tricking corporate workers who simply want a desktop version of a popular AI assistant.
Between July 21 and July 22, 2026, at least 29 organizations saw unusual software installs and hidden persistence on their systems after staff searched for the Claude desktop app.
The attack begins with paid ads on Microsoft Bing. When someone types a normal query for the app, sponsored results appear that look trustworthy. One of those ads even points to the real Claude.ai website, which lowers suspicion and makes the trap harder to spot.
Analysts from Huntress identified the activity after their security operations center flagged waves of odd executable installs, Defender exclusions, and strange scheduled tasks tied to a file named ClaudeDesktop.exe.
Huntress said in a report shared with Cyber Security News (CSN) that the campaign, which they call FakeAgent, funnels victims through a malicious public Claude Artifact and ultimately delivers SectopRAT, a remote access trojan that steals credit cards, passwords, browser data, and personal files.
Before Anthropic removed the bad Artifact, it had already drawn about 7,100 page views. That volume shows how quickly paid search ads and trusted domains can combine to reach busy office users who only meant to install helpful software.
The campaign also used heavy anti-analysis tricks, including packing and graphics hardware checks that try to spot virtual machines. Those steps slow down defenders and let the malware stay quiet longer on real corporate machines.
FakeAgent Campaign Uses Malicious Bing Ads
The infection chain starts with a simple Bing search for “CLAUDE DESKTOP APP.” Sponsored results fill the top of the page with lookalike download sites, a pattern also seen in earlier weaponized PuTTY Bing ads that abused the same search ads model.

Mixed among them sits a sponsored link that lands on the legitimate Claude.ai domain, specifically a public Artifact page.
Public Artifacts are user-generated pages that anyone can share. Claude itself warns that the content is unverified, yet many people still trust anything hosted on the official domain.

Clicking Download on the fake page sends the user first to claude.ai.download-app.us and then to downloading-api.it.com, where ClaudeDesktop.exe is offered.
Figure 1 in the Huntress material shows the Bing results packed with those sponsored traps. Figure 2 shows the Artifact page dressed up as a normal Claude Desktop installer. Because the journey began on a real Claude.ai address, many users ran the file without a second thought.
ClaudeDesktop.exe is not the real app. It is a renamed, signed JetBrains helper that loads a tampered library beside it, a classic DLL sideloading malware attack that lets malicious code run under a trusted process name.
An identical copy called DockerDesktop.exe is later written as a scheduled task so the infection can restart after reboot.
A second signed program, sslconf.exe, appears under an EdgeUpdate folder and loads yet another altered library.
That stage checks graphics hardware and video memory to avoid sandboxes, then decrypts a hidden payload with a graphics shader instead of ordinary CPU code.
The final result is SectopRAT, which hunts browser logins, cookies, autofill data, credit cards, and messaging apps.
Command addresses are not hard-coded in plain text. They are pulled from Ethereum blockchain contracts, a method known as EtherHiding that lets operators change servers by posting new transactions that are hard to take down.
How Corporate Users Get Infected
Corporate staff often search for AI desktop tools during work hours and click the first convenient result.
That habit turns everyday research into a direct path for malware when ads and trusted domains are abused together.
Similar tricks have already appeared in shared Claude chats malware campaigns that also rode the Claude brand to look real.
Once inside, SectopRAT gives attackers remote control and a steady stream of stolen credentials and files.
Persistence through scheduled tasks and Defender exclusions keeps the foothold alive even after a reboot or a basic cleanup attempt. Huntress linked the same operator style to earlier fake Docker Desktop lures, showing this is not a one-off experiment.

Defenders should treat top-level domains with caution and never assume a familiar brand name equals a safe download.
Users should type official vendor addresses directly instead of trusting sponsored search results, and security teams should watch for unexpected ClaudeDesktop.exe or DockerDesktop.exe activity, new EdgeUpdate paths, and odd scheduled tasks.
Clear remote access Trojan practices still matter: keep software updated, limit unnecessary admin rights, and verify every installer against the vendor’s own site.
Huntress reported the malicious Artifact to Anthropic, and it was removed. The episode still underlines a wider lesson. As more people chase AI tools, both search ads and AI hosting features become attractive stages for malware that looks legitimate until it is far too late.
Indicators of compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| URL | claude.ai/public/artifacts/ca456f1f-44c0-42af-b329-4f1c7534a877 | Malicious Claude Desktop download Artifact page |
| Domain | download-app.us | Redirect domain for ClaudeDesktop.exe |
| Domain | claude.ai.download-app.us | Attacker-controlled download redirect host |
| URL | downloading-api.it.com/html/claude/win | Path serving the malicious executable |
| Domain | 5ca8758c-02d0-4a72-89c8-d468b66dda41.com | Backup SectopRAT domain |
| IP Address | 2.24.131.246 | Active SectopRAT command-and-control server |
| IP Address | 107.189.24.67 | Historical C2 address (2025-05-30) |
| IP Address | 104.194.133.210 | Historical C2 address (2025-07-13) |
| IP Address | 107.189.26.86 | Historical C2 address (2025-07-26) |
| IP Address | 107.189.21.86 | Historical C2 address (2025-08-11) |
| IP Address | 45.59.124.17 | Historical C2 address (2025-08-22) |
| IP Address | 45.59.125.228 | Historical C2 address (2025-09-05) |
| IP Address | 45.59.122.82 | Historical C2 address (2025-09-14) |
| IP Address | 107.189.17.143 | Historical C2 address (2025-09-24) |
| IP Address | 45.59.122.134 | Historical C2 address (2025-11-23) |
| IP Address | 45.59.122.235 | Historical C2 address (2025-12-03) |
| IP Address | 107.189.22.118 | Historical C2 address (2025-12-09) |
| IP Address | 107.189.20.32 | Historical C2 address (2025-12-16) |
| IP Address | 107.189.20.95 | Historical C2 address (2025-12-29) |
| IP Address | 107.189.24.255 | Historical C2 address (2026-01-10) |
| IP Address | 45.59.117.145 | Historical C2 address (2026-01-28) |
| IP Address | 45.59.114.190 | Historical C2 address (2026-03-13) |
| IP Address | 45.59.123.122 | Historical C2 address (2026-04-03) |
| IP Address | 45.59.117.67 | Historical C2 address (2026-04-14) |
| IP Address | 195.110.58.222 | Historical C2 address (2026-04-20) |
| IP Address | 191.101.80.211 | Historical C2 address (2026-05-12) |
| Blockchain | 0xe012d0f34cde9b870e9d9ed566ea5f8fd9b92228 | SectopRAT BSC contract |
| Blockchain | 0xc1907d7be91f95903ad66d775c397302e7dd9228 | libcef.dll stager BSC contract |
| SHA256 | 1cd58cfba596da296ab1878d74023e00c399345a1b6c2a0e5446c53563f4e3bb | tempdir.dll |
| SHA256 | 26bae4d7012bf59847ab4036a065419c3d4ca47e020479f55b3b2c6d0d21394a | libcef.dll |
| SHA256 | 1fe3646d27d286db8123297e06ae7badf3e26f352a04f91b6d82c28869a91664 | Embedded SectopRAT payload |
| SHA256 | f8acb8f5cf88b77a4c27d7fd6856aa299bb178e85f9963c2fbd447d818da3ed0 | DockerDesktop.exe / ClaudeDesktop.exe (benign host binary) |
| SHA256 | fd826215add30c1319eefa291b6eaf8ddfa7720cfe816c49aef6fe8a88de7939 | SSLConf.exe (benign host binary) |
| File Name | ClaudeDesktop.exe | Initial malicious downloader staged as Claude app |
| File Name | DockerDesktop.exe | Persistent scheduled-task copy of the loader |
| File Name | libcef.dll | Tampered DLL used for sideloading |
| File Name | tempdir.dll | Second-stage sideloaded malicious DLL |
| File Name | sslconf.exe | Signed IBM SPSS binary used for further sideloading |
| File Name | appcfg.dat | Encrypted on-disk payload container |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.