As cited
Copy frozen at (site build).
threat intel
Inside FakeAgent: How a Claude Desktop Malvertising Campaign Hit 29 Organizations with SectopRAT
Huntress identified a malvertising campaign between July 21 and July 22 that used malicious Claude Artifacts hosted on legitimate Anthropic domains to deliver SectopRAT stealer malware to 29 organizations. Attackers leveraged Claude's public sharing feature to host and distribute the malware under the guise of legitimate content.
Why it matters: Organizations using Claude Desktop are exposed to this attack vector; defenders should scrutinize Claude Artifacts from untrusted sources and monitor for SectopRAT indicators, as legitimate platform domains can host malicious payloads.
- Source published
- First seen by Cybersecurity Tracker