# Inside FakeAgent: How a Claude Desktop Malvertising Campaign Hit 29 Organizations with SectopRAT

DevFeed: [Inside FakeAgent: How a Claude Desktop Malvertising Campaign Hit 29 Organizations with SectopRAT](<https://devfeed.tech/articles/inside-fakeagent-how-a-claude-desktop-malvertising-campaign-hit-29-organizations-with-sectoprat-54346.md>)

Original publisher: [Read original article](<https://www.huntress.com/blog/fakeagent-claude-desktop-malvertising-ends-in-dotnet-rat>)

Author: Michael Tigges

Published: 2026-07-22T20:00:00Z

Content type: article

Language: en

Sources: [Huntress Blog](<https://devfeed.tech/sources/huntress-blog.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [Remote Access Trojan](<https://devfeed.tech/topics/remote-access-trojan.md>), [C2](<https://devfeed.tech/topics/c2.md>), [Claude](<https://devfeed.tech/topics/claude.md>), [Ethereum](<https://devfeed.tech/topics/ethereum.md>), [Blockchain](<https://devfeed.tech/topics/blockchain.md>), [Search engine optimization (SEO)](<https://devfeed.tech/topics/seo.md>)

Tags: [attacks](<https://devfeed.tech/tags/attacks.md>), [blockchain](<https://devfeed.tech/tags/blockchain.md>), [c2](<https://devfeed.tech/tags/c2.md>), [claude](<https://devfeed.tech/tags/claude.md>), [command-and-control](<https://devfeed.tech/tags/command-and-control.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [ethereum](<https://devfeed.tech/tags/ethereum.md>), [malware](<https://devfeed.tech/tags/malware.md>), [remote-access-trojan](<https://devfeed.tech/tags/remote-access-trojan.md>), [sectoprat](<https://devfeed.tech/tags/sectoprat.md>), [seo](<https://devfeed.tech/tags/seo.md>)

## AI overview

Huntress investigates FakeAgent, a malvertising campaign that used a malicious public Claude Artifact and fake Claude Desktop download pages to distribute SectopRAT. The remote access trojan stole credit-card data, personal information, files, and passwords, while the campaign used Ethereum-based command-and-control data and anti-analysis techniques.

## Source excerpt

On July 21 and July 22, Huntress observed a number of attacks that started with a malicious public Claude Artifact hosted on a legitimate Claude domain, and ended in organizations being infected by the SectopRAT stealer.