CYBERSECURITYTRACKER
TRACKING
Permanent story citation

Inside FakeAgent: How a Claude Desktop Malvertising Campaign Hit 29 Organizations with SectopRAT

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 4660

As cited

Copy frozen at (site build).

threat intel

Inside FakeAgent: How a Claude Desktop Malvertising Campaign Hit 29 Organizations with SectopRAT

Huntress identified a malvertising campaign between July 21 and July 22 that used malicious Claude Artifacts hosted on legitimate Anthropic domains to deliver SectopRAT stealer malware to 29 organizations. Attackers leveraged Claude's public sharing feature to host and distribute the malware under the guise of legitimate content.

Why it matters: Organizations using Claude Desktop are exposed to this attack vector; defenders should scrutinize Claude Artifacts from untrusted sources and monitor for SectopRAT indicators, as legitimate platform domains can host malicious payloads.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary