Fake Claude Desktop Ads Drop SectopRAT Through Claude Artifact
Huntress reported on July 22, 2026 that a FakeAgent malvertising campaign used sponsored Bing results and a public claude.ai Artifact to push a fake Claude Desktop installer. The campaign affected at least 29 organizations between July 21 and July 22 before the malicious Artifact was removed.
The important warning is simple: a trusted domain in the first click does not prove the download is safe. In this case, the first visible page was hosted under Claude’s own domain, but the Download button redirected users to attacker-controlled infrastructure and served ClaudeDesktop.exe.
How the FakeAgent Chain Worked
Huntress says victims searching for the Claude desktop app saw malicious sponsored results on Bing. One ad sent users to a public Artifact at claude[.]ai/public/artifacts/ca456f1f-44c0-42af-b329-4f1c7534a877. The page looked like a Claude Desktop download page and had more than 7,100 views before takedown.
Clicking Download redirected through claude.ai.download-app[.]us and then downloading-api.it[.]com/html/claude/win. From there, the user received a Windows download named ClaudeDesktop.exe. Help Net Security also summarized the Bing-ad route and the fake Claude app angle in its July 23 coverage.
Adware Guru has seen the same trust-bridge pattern in other AI-themed lures, including ChatGPT share links abused for fake outage malware downloads and fake ChatGPT and Claude installers hosted through trusted developer platforms. FakeAgent is distinct because the lure lived as a public Claude Artifact and then moved into a signed-binary sideloading chain.
Why ClaudeDesktop.exe Was Not a Normal Installer
Huntress found that the user-facing ClaudeDesktop.exe was actually a renamed JetBrains Chromium Embedded Framework helper, not the official Claude Desktop app. The malicious code was carried by a tampered libcef.dll placed beside that signed executable, a technique known as DLL sideloading.
The bundle also used DockerDesktop.exe for persistence through a scheduled task, a clue that Huntress tied to an earlier fake Docker Desktop campaign. The final malware was identified as SectopRAT, with the primary C2 listed as 2.24.131[.]246 and a backup domain 5ca8758c-02d0-4a72-89c8-d468b66dda41[.]com.
SectopRAT is not adware. It is a remote access trojan that can expose browser data, passwords, files, payment details, and other local information. The reason it matters for this site is the delivery method: sponsored-search malvertising plus a fake software-download page, the same surface that also drives fake download redirects, unwanted installers, and browser-abuse campaigns.
Quick Check for Windows Users
If you recently searched for Claude Desktop, clicked a sponsored result, and downloaded a Windows file named ClaudeDesktop.exe from a page reached through a public Artifact or a non-Anthropic download domain, treat the device as potentially compromised.
Check browser downloads, recent ZIP or EXE files, and new scheduled tasks. Look for suspicious files or folders tied to ClaudeDesktop.exe, DockerDesktop.exe, libcef.dll, tempdir.dll, SSLConf.exe, or appcfg.dat. These names are useful clues, but malware operators can change filenames, so absence of one name does not prove the system is clean.
Also review browser accounts and saved sessions. A RAT or stealer can create follow-on risk even after the visible installer is deleted. If the issue is only recurring website pop-ups or fake alerts, use the browser notification scam removal guide; FakeAgent is a different, executable malware case.
What to Do If You Ran It
Disconnect the machine from sensitive accounts, avoid banking or password-manager use on that device, and run a full security scan. Change important passwords from a clean device, revoke unknown sessions, and check for new startup items or scheduled tasks. If the device belongs to a workplace, report the download path and filenames to IT so they can search for the same indicators across other endpoints.
For future downloads, do not let a search ad outrank the vendor’s official download path. Type the vendor’s site yourself, use a trusted app store when available, and be especially careful when a page hosted on a public sharing, artifact, code, or document feature asks you to install software from a different domain.



