Skip to content
Malware

FakeAgent Campaign Uses Malicious Bing Ads and Claude.ai Artifacts to Infect Corporate Users

A dangerous new malware campaign is tricking corporate workers who simply want a desktop version of a popular AI assistant. Between July 21 and July 22, 2026, at least 29 organizations saw unusual software installs and hidden persistence on their systems after staff searched for the Claude desktop a...

· Jul 24, 2026 · 7 min read · 👁 1 views
FakeAgent Campaign Uses Malicious Bing Ads and Claude.ai Artifacts to Infect Corporate Users

A dangerous new malware campaign is tricking corporate workers who simply want a desktop version of a popular AI assistant.

Between July 21 and July 22, 2026, at least 29 organizations saw unusual software installs and hidden persistence on their systems after staff searched for the Claude desktop app.

The attack begins with paid ads on Microsoft Bing. When someone types a normal query for the app, sponsored results appear that look trustworthy. One of those ads even points to the real Claude.ai website, which lowers suspicion and makes the trap harder to spot.

Analysts from Huntress identified the activity after their security operations center flagged waves of odd executable installs, Defender exclusions, and strange scheduled tasks tied to a file named ClaudeDesktop.exe.

Huntress said in a report shared with Cyber Security News (CSN) that the campaign, which they call FakeAgent, funnels victims through a malicious public Claude Artifact and ultimately delivers SectopRAT, a remote access trojan that steals credit cards, passwords, browser data, and personal files.

Before Anthropic removed the bad Artifact, it had already drawn about 7,100 page views. That volume shows how quickly paid search ads and trusted domains can combine to reach busy office users who only meant to install helpful software.

The campaign also used heavy anti-analysis tricks, including packing and graphics hardware checks that try to spot virtual machines. Those steps slow down defenders and let the malware stay quiet longer on real corporate machines.

FakeAgent Campaign Uses Malicious Bing Ads

The infection chain starts with a simple Bing search for “CLAUDE DESKTOP APP.” Sponsored results fill the top of the page with lookalike download sites, a pattern also seen in earlier weaponized PuTTY Bing ads that abused the same search ads model.

Bing search results with several malicious sponsored advertisements (Source - Huntress)
Bing search results with several malicious sponsored advertisements (Source – Huntress)

Mixed among them sits a sponsored link that lands on the legitimate Claude.ai domain, specifically a public Artifact page.

Public Artifacts are user-generated pages that anyone can share. Claude itself warns that the content is unverified, yet many people still trust anything hosted on the official domain.

Claude Desktop - Cowork phishing page hosted as a Claude artifact (Source - Huntress)
Claude Desktop – Cowork phishing page hosted as a Claude artifact (Source – Huntress)

Clicking Download on the fake page sends the user first to claude.ai.download-app.us and then to downloading-api.it.com, where ClaudeDesktop.exe is offered.

Figure 1 in the Huntress material shows the Bing results packed with those sponsored traps. Figure 2 shows the Artifact page dressed up as a normal Claude Desktop installer. Because the journey began on a real Claude.ai address, many users ran the file without a second thought.

ClaudeDesktop.exe is not the real app. It is a renamed, signed JetBrains helper that loads a tampered library beside it, a classic DLL sideloading malware attack that lets malicious code run under a trusted process name.

An identical copy called DockerDesktop.exe is later written as a scheduled task so the infection can restart after reboot.

A second signed program, sslconf.exe, appears under an EdgeUpdate folder and loads yet another altered library.

That stage checks graphics hardware and video memory to avoid sandboxes, then decrypts a hidden payload with a graphics shader instead of ordinary CPU code.

The final result is SectopRAT, which hunts browser logins, cookies, autofill data, credit cards, and messaging apps.

Command addresses are not hard-coded in plain text. They are pulled from Ethereum blockchain contracts, a method known as EtherHiding that lets operators change servers by posting new transactions that are hard to take down.

How Corporate Users Get Infected

Corporate staff often search for AI desktop tools during work hours and click the first convenient result.

That habit turns everyday research into a direct path for malware when ads and trusted domains are abused together.

Similar tricks have already appeared in shared Claude chats malware campaigns that also rode the Claude brand to look real.

Once inside, SectopRAT gives attackers remote control and a steady stream of stolen credentials and files.

Persistence through scheduled tasks and Defender exclusions keeps the foothold alive even after a reboot or a basic cleanup attempt. Huntress linked the same operator style to earlier fake Docker Desktop lures, showing this is not a one-off experiment.

Deobfuscated LLM representation of embedded .NET code (Source - Huntress)
Deobfuscated LLM representation of embedded .NET code (Source – Huntress)

Defenders should treat top-level domains with caution and never assume a familiar brand name equals a safe download.

Users should type official vendor addresses directly instead of trusting sponsored search results, and security teams should watch for unexpected ClaudeDesktop.exe or DockerDesktop.exe activity, new EdgeUpdate paths, and odd scheduled tasks.

Clear remote access Trojan practices still matter: keep software updated, limit unnecessary admin rights, and verify every installer against the vendor’s own site.

Huntress reported the malicious Artifact to Anthropic, and it was removed. The episode still underlines a wider lesson. As more people chase AI tools, both search ads and AI hosting features become attractive stages for malware that looks legitimate until it is far too late.

Indicators of compromise (IoCs):-

TypeIndicatorDescription
URLclaude.ai/public/artifacts/ca456f1f-44c0-42af-b329-4f1c7534a877Malicious Claude Desktop download Artifact page
Domaindownload-app.usRedirect domain for ClaudeDesktop.exe
Domainclaude.ai.download-app.usAttacker-controlled download redirect host
URLdownloading-api.it.com/html/claude/winPath serving the malicious executable
Domain5ca8758c-02d0-4a72-89c8-d468b66dda41.comBackup SectopRAT domain
IP Address2.24.131.246Active SectopRAT command-and-control server
IP Address107.189.24.67Historical C2 address (2025-05-30)
IP Address104.194.133.210Historical C2 address (2025-07-13)
IP Address107.189.26.86Historical C2 address (2025-07-26)
IP Address107.189.21.86Historical C2 address (2025-08-11)
IP Address45.59.124.17Historical C2 address (2025-08-22)
IP Address45.59.125.228Historical C2 address (2025-09-05)
IP Address45.59.122.82Historical C2 address (2025-09-14)
IP Address107.189.17.143Historical C2 address (2025-09-24)
IP Address45.59.122.134Historical C2 address (2025-11-23)
IP Address45.59.122.235Historical C2 address (2025-12-03)
IP Address107.189.22.118Historical C2 address (2025-12-09)
IP Address107.189.20.32Historical C2 address (2025-12-16)
IP Address107.189.20.95Historical C2 address (2025-12-29)
IP Address107.189.24.255Historical C2 address (2026-01-10)
IP Address45.59.117.145Historical C2 address (2026-01-28)
IP Address45.59.114.190Historical C2 address (2026-03-13)
IP Address45.59.123.122Historical C2 address (2026-04-03)
IP Address45.59.117.67Historical C2 address (2026-04-14)
IP Address195.110.58.222Historical C2 address (2026-04-20)
IP Address191.101.80.211Historical C2 address (2026-05-12)
Blockchain0xe012d0f34cde9b870e9d9ed566ea5f8fd9b92228SectopRAT BSC contract
Blockchain0xc1907d7be91f95903ad66d775c397302e7dd9228libcef.dll stager BSC contract
SHA2561cd58cfba596da296ab1878d74023e00c399345a1b6c2a0e5446c53563f4e3bbtempdir.dll
SHA25626bae4d7012bf59847ab4036a065419c3d4ca47e020479f55b3b2c6d0d21394alibcef.dll
SHA2561fe3646d27d286db8123297e06ae7badf3e26f352a04f91b6d82c28869a91664Embedded SectopRAT payload
SHA256f8acb8f5cf88b77a4c27d7fd6856aa299bb178e85f9963c2fbd447d818da3ed0DockerDesktop.exe / ClaudeDesktop.exe (benign host binary)
SHA256fd826215add30c1319eefa291b6eaf8ddfa7720cfe816c49aef6fe8a88de7939SSLConf.exe (benign host binary)
File NameClaudeDesktop.exeInitial malicious downloader staged as Claude app
File NameDockerDesktop.exePersistent scheduled-task copy of the loader
File Namelibcef.dllTampered DLL used for sideloading
File Nametempdir.dllSecond-stage sideloaded malicious DLL
File Namesslconf.exeSigned IBM SPSS binary used for further sideloading
File Nameappcfg.datEncrypted on-disk payload container

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Source: CybersecurityNews.com

Follow ShomoySoft for more: Follow on Facebook

💬 Comments (0)

Login to join the discussion.

No comments yet. Be the first!

Recommended for you