As cited
Copy frozen at (site build).
threat intel
Fake Claude app promoted by Bing ads pushes SectopRAT malware
Attackers are using malvertising on Bing search results to distribute a fake Claude desktop application installer that harvests credentials and installs the SectopRAT remote access trojan. The malicious installer is hosted on a subdomain of the legitimate Claude.ai domain, creating a convincing social engineering lure.
Why it matters: Practitioners managing security awareness and incident response must track this active malvertising campaign because it targets users searching for a widely adopted AI assistant, establishing foothold for RAT infections and credential theft.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Fake Claude app promoted by Bing ads pushes SectopRAT malware
A malvertising campaign on Bing promotes a counterfeit Claude desktop application installer that distributes SectopRAT malware. The fake app is hosted on a legitimate Claude.ai domain, exploiting user trust in the official platform to deliver the remote access trojan.
Why it matters: Developers and end users searching for Claude tooling on Bing are at immediate risk of downloading malware disguised as legitimate software; organizations should alert staff to verify download sources and watch for SectopRAT indicators of compromise.
- Source published
- First seen by Cybersecurity Tracker