CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Fake Claude app promoted by Bing ads pushes SectopRAT malware

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3135

As cited

Copy frozen at (site build).

threat intel

Fake Claude app promoted by Bing ads pushes SectopRAT malware

Attackers are using malvertising on Bing search results to distribute a fake Claude desktop application installer that harvests credentials and installs the SectopRAT remote access trojan. The malicious installer is hosted on a subdomain of the legitimate Claude.ai domain, creating a convincing social engineering lure.

Why it matters: Practitioners managing security awareness and incident response must track this active malvertising campaign because it targets users searching for a widely adopted AI assistant, establishing foothold for RAT infections and credential theft.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Fake Claude app promoted by Bing ads pushes SectopRAT malware

A malvertising campaign on Bing promotes a counterfeit Claude desktop application installer that distributes SectopRAT malware. The fake app is hosted on a legitimate Claude.ai domain, exploiting user trust in the official platform to deliver the remote access trojan.

Why it matters: Developers and end users searching for Claude tooling on Bing are at immediate risk of downloading malware disguised as legitimate software; organizations should alert staff to verify download sources and watch for SectopRAT indicators of compromise.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary