TheVortiq
Inteligencia Artificial

Malware Hidden in Claude.ai Domain Distributes RAT via Bing Ads

Cybercriminals Exploit Claude Artifacts to Impersonate Claude Desktop Download and Spread SectopRAT, Infecting at Least 29 Organizations

July 24, 2026 · 3 min read

red padlock on black computer keyboard

TL;DR: Attackers created a fake Claude Artifact mimicking the Claude Desktop download. Promoted via Bing Ads, it redirected to a malicious domain that downloaded SectopRAT, infecting 29 organizations in two days.

What Happened?

Between July 21 and 22, 2026, Huntress security team detected a wave of unusual executables, Defender exclusions, and anomalous persistence across 29 organizations, all originating from a file named ClaudeDesktop.exe. Investigation revealed that attackers had created a malicious Claude Artifact hosted on the legitimate domain claude.ai, which mimicked the Claude Desktop download page. Victims reached this artifact through sponsored Bing ads appearing among top results when searching for 'Claude Desktop App'.

The artifact redirected to an attacker-controlled domain, where SectopRAT was downloaded—a remote access trojan (RAT) capable of stealing passwords, banking data, personal files, and more. Although Claude added a disclaimer on artifacts stating that the content is unverified, the fact that the link belonged to the official domain made it harder to detect the deception.

Why Is This Important?

This incident highlights a vulnerability in the trust users place in AI company domains. While Claude Artifacts are useful tools for sharing code and prototypes, their ability to be hosted on Anthropic's main domain makes them an attractive vector for malvertising. The campaign successfully deceived users who would otherwise distrust suspicious links, precisely because the initial link pointed to a trusted domain.

Moreover, the use of Bing Ads to promote the artifact demonstrates that cybercriminals are refining their tactics to exploit legitimate advertising platforms. Although search engines have implemented measures against malvertising, this case shows that combining paid ads with content hosted on official domains can bypass traditional filters.

Consequences and Reactions

Claude removed the malicious artifact after it accumulated over 7,000 views. However, other organizations beyond Huntress's scope are likely also infected. SectopRAT is a known malware that allows attackers to take remote control of the device, steal sensitive information, and establish persistence. Potential victims range from individual users to companies seeking to download the legitimate Claude application.

This attack adds to a growing trend of ClickFix attacks and other scams using AI tools as lures. Similar cases have been seen in the past with infostealers disguised as Claude Code and other AI applications. The cybersecurity community has repeatedly warned about the risks of malvertising, but this incident underscores the need for platform providers like Anthropic to implement stricter controls over user-generated content hosted on their domains.

What Readers Should Know

  • Always verify the full URL: Even if the domain is legitimate (claude.ai), the specific path can lead to malicious content. Pay attention to the URL structure, especially if it includes /public/artifacts/.
  • Be wary of search engine ads: Sponsored results can be manipulated. If you are looking for a known application, access the official site directly by typing the URL in the browser or using a bookmark.
  • Use security tools: Keep your antivirus updated and consider advanced malware detection solutions. Defender exclusions are a red flag.
  • Train employees: Organizations should educate their staff about the risks of malvertising and social engineering, especially when it comes to software downloads.

Broader Context

This attack is not an isolated case. The combination of generative AI platforms, online advertising, and malware is a worrying trend. As more companies adopt AI tools, cybercriminals seek to exploit trust in these brands. Claude Artifacts, being user-generated content, lack the same verification as official product pages. Anthropic has added disclaimers, but these can go unnoticed by hurried users.

The use of Bing Ads to promote the artifact also raises questions about search engine responsibility. Microsoft, owner of Bing, has implemented policies against malvertising, but attackers constantly find ways to evade them. In this case, the ad led to a legitimate domain, making automatic detection difficult.

Conclusion

The SectopRAT campaign via Claude.ai is a reminder that trust in official domains is not enough. Users must be cautious even when the link appears legitimate, and tech companies must strengthen security for their user-generated content platforms. Collaboration between security teams, AI providers, and search engines will be key to mitigating these threats in the future.

Keep reading