A malvertising campaign on the Bing search service is pushing a fake Claude desktop app installer hosted on a legitimate Claude.ai domain to deliver the SectopRAT malware.
At least 29 organizations were compromised between July 21–22 during the malicious operation, which researchers call FakeAgent.
The attackers used a malicious Claude Artifact hosted on Claude’s legitimate domain, a tactic that has been used at the beginning of the year to push macOS malware via ClickFix lures.
