Attackers used manipulated Bing ads to distribute SectopRAT malware, compromising at least 29 organizations.
Security researchers at IT services provider Huntress have uncovered a malvertising campaign leveraging fraudulent advertisements on the Bing search platform. The ads led to a Claude Artifact hosted on the official Claude.ai domain. The artifact linked to an external website from which a fake installer named ClaudeDesktop.exe was downloaded. Before its removal by provider Anthropic, the artifact was accessed approximately 7,100 times.
The downloaded file was a legitimate JetBrains Chromium component that utilized DLL sideloading to load a malicious library named libcef.dll. Through this mechanism, the system installed the SectopRAT malware onto the target machine. Persistence on the compromised system was established using an additional executable named DockerDesktop.exe, which created a scheduled task in Windows Task Scheduler.
Capabilities of the SectopRAT Malware
SectopRAT, also known as ArechClient2, is a remote access trojan equipped with information-stealing capabilities. The software has been active since 2019 and features Hidden Virtual Network Computing (HVNC) capabilities, allowing attackers direct, real-time remote access and interaction with the affected system.
The malware aims to steal user passwords, credit card details, browser logins, cookies, FTP credentials, and data from messaging applications such as Discord and Telegram. To determine the active command-and-control server address, the software uses the EtherHiding technique via transactions on the Ethereum BNB Smart Chain.
Analysis and Campaign Attribution
In the campaign, tracked by researchers under the name FakeAgent, at least 29 organizations were compromised between July 21 and July 22, 2026. The loaders and intermediate stages employed various anti-analysis mechanisms, including VMProtect packing, graphics card and VRAM checks, and virtual machine detection.
During their investigation, analysts identified ten server domains registered under the same email address since December 2025. One of these domains was previously linked to the distribution of StealC malware and was seized as part of the international Operation Endgame. A definitive attribution of the FakeAgent campaign to a known threat group has not yet been established.
(red)