>samit_hota
Back to security news
SN-2026-175HighOpen

Bing Ads Malvertising Pushes Fake Claude Desktop App Delivering SectopRAT

Samit Hota·
CVE ID
N/A
Affected Products / Orgs
Microsoft Bing Search, Windows OS, Anthropic Claude Users
#news#malware#fake

A malicious advertising campaign running on the Bing search engine is promoting a fake Claude desktop app designed to trick users seeking Anthropic’s AI assistant into executing malware. Victims who interact with the sponsored advertisements are directed to downloading a malicious installer that ultimately delivers the SectopRAT malware trojan.

Malvertising and Delivery Vector

Threat actors are purchasing prominent sponsored ad positions on Bing search result pages for keywords associated with Anthropic, Claude AI, and desktop client downloads. Because Anthropic offers official access primarily through web applications and mobile clients rather than a standalone Windows desktop installation binary, users searching for native desktop executables represent a high-value target.

To bypass initial automated ad verification checks and gain victim trust, the Bing ads malvertising scheme leverages open redirects and compromised infrastructure linked to legitimate Claude.ai domains. Clicking the ad routes the victim through a series of cloaked redirect servers before serving a malicious installer binary disguised as an official desktop setup wizard.

SectopRAT Malware Capabilities

Upon execution, the installer drops SectopRAT (also known as ArechClient), a feature-rich remote access trojan built on the .NET framework. Once active on an infected Windows endpoint, SectopRAT provides threat actors with extensive administrative control, including:

  • Disabling endpoint security controls, local antivirus software, and Windows Defender features.
  • Establishing encrypted command-and-control (C2) communication channels to receive remote execution commands.
  • Harvesting saved browser credentials, web session cookies, autofill logs, and local cryptocurrency wallets.
  • Instantiating reverse SOCKS proxies to allow threat actors to pivot deeper into enterprise internal networks.

Mitigation and Defense

To counter malvertising risks, enterprise security teams should deploy central ad-blocking controls across web browsers and restrict local non-administrative installation privileges on Windows endpoints. Endpoint security policies should be configured to block binary execution originating from browser download directories and inspect network egress logs for persistent C2 traffic associated with SectopRAT infrastructure.

Found something similar in your stack?

Let's find out before it becomes an incident.

Book an advisory call