Bing Ads Malvertising Pushes Fake Claude Desktop App Delivering SectopRAT
- CVE ID
- N/A
- Affected Products / Orgs
- Microsoft Bing Search, Windows OS, Anthropic Claude Users
A malicious advertising campaign running on the Bing search engine is promoting a fake Claude desktop app designed to trick users seeking Anthropic’s AI assistant into executing malware. Victims who interact with the sponsored advertisements are directed to downloading a malicious installer that ultimately delivers the SectopRAT malware trojan.
Malvertising and Delivery Vector
Threat actors are purchasing prominent sponsored ad positions on Bing search result pages for keywords associated with Anthropic, Claude AI, and desktop client downloads. Because Anthropic offers official access primarily through web applications and mobile clients rather than a standalone Windows desktop installation binary, users searching for native desktop executables represent a high-value target.
To bypass initial automated ad verification checks and gain victim trust, the Bing ads malvertising scheme leverages open redirects and compromised infrastructure linked to legitimate Claude.ai domains. Clicking the ad routes the victim through a series of cloaked redirect servers before serving a malicious installer binary disguised as an official desktop setup wizard.
SectopRAT Malware Capabilities
Upon execution, the installer drops SectopRAT (also known as ArechClient), a feature-rich remote access trojan built on the .NET framework. Once active on an infected Windows endpoint, SectopRAT provides threat actors with extensive administrative control, including:
- Disabling endpoint security controls, local antivirus software, and Windows Defender features.
- Establishing encrypted command-and-control (C2) communication channels to receive remote execution commands.
- Harvesting saved browser credentials, web session cookies, autofill logs, and local cryptocurrency wallets.
- Instantiating reverse SOCKS proxies to allow threat actors to pivot deeper into enterprise internal networks.
Mitigation and Defense
To counter malvertising risks, enterprise security teams should deploy central ad-blocking controls across web browsers and restrict local non-administrative installation privileges on Windows endpoints. Endpoint security policies should be configured to block binary execution originating from browser download directories and inspect network egress logs for persistent C2 traffic associated with SectopRAT infrastructure.
Related content
Anthropic Claude Models Escape Sandbox Egress, Breach Orgs and Publish PyPI Malware
Security NewsInside a Post-Breach Intrusion: SQL Injection, BadIIS, and Evasion Techniques
Security NewsFake Roblox Xeno Script Launcher Delivers Multi-Stage Java RAT and Infostealer
Security NewsMicrosoft Patches RoguePlanet (CVE-2026-50656) Local Privilege Escalation in Defender
Found something similar in your stack?
Let's find out before it becomes an incident.
Book an advisory call