Skip to content
feed: live
>_ 0dayNews
threat intel

Fake Claude Installer in Bing Ads Drops SectopRAT

Active Bing malvertising is serving a fake Claude desktop app installer that delivers SectopRAT. BleepingComputer reports the installer is hosted on a legitimate Claude.ai domain.

Fake Claude Installer in Bing Ads Drops SectopRAT
Image: 0dayNews / 0dayNews Editorial · All rights reserved
loop Loop · Published · 2 min read

Bing search ad placements for Claude-related queries are distributing a fake installer that drops SectopRAT on execution. BleepingComputer reported the campaign on July 23, 2026, noting the installer appears hosted on a legitimate Claude.ai domain — an unusual wrinkle for malvertising, where lookalike or typosquat domains are the standard delivery path.

SectopRAT, also tracked as ArechClient2, is a .NET-based remote access trojan documented across multiple malvertising campaigns over several years. Documented capabilities include browser credential harvesting, session cookie theft, screen capture, and cryptocurrency wallet file targeting. Indicators of compromise from this specific campaign are in BleepingComputer’s write-up.

The domain detail

Routine malvertising defense tells users to check the URL before downloading. Ad looks right, you click, domain looks wrong — you back out. That response chain assumes the delivery domain is what’s off.

BleepingComputer’s analysis describes the installer as served from a legitimate Claude.ai domain rather than a spoofed one. If that characterization is accurate, URL verification doesn’t protect you here. The Bing ad infrastructure handles the initial routing; the destination at the end of the click can look correct.

This isn’t the first time AI tool brands have been impersonated in malvertising campaigns — the category has widened with the growth in AI assistant adoption. Earlier today, a separate security disclosure detailed a sandbox escape vulnerability in Anthropic’s Claude Cowork environment: Claude Cowork flaw could let AI agents access Mac files outside the VM. Unrelated technically, but relevant context for anyone managing endpoints where AI tooling is being installed by users across the organization.

What to do

Don’t install Claude from a search result. Navigate directly to claude.ai. The official desktop client is distributed from there.

If someone on your network installed a Claude app via a Bing search result recently: treat the endpoint as potentially compromised. Rotate browser-stored credentials. Audit running processes and scheduled tasks for persistence mechanisms. Review outbound connections for SectopRAT command-and-control patterns. Full indicators are in BleepingComputer’s coverage.

For security teams managing endpoints at scale: domain-based controls are not the right detection layer here. Endpoint detection tuned to SectopRAT’s installation and runtime behavior — unsigned installer execution, .NET runtime process ancestry, browser credential access patterns — is where the signal is. The initial ad click looks clean; the installer is where detection has traction.

For broader campaign context and related malware-delivery coverage, see the Threat Intel & Field Notes topic hub.

Found this useful? Share it.