Researchers at Huntress have disclosed a malvertising campaign that abused a public artifact hosted on Anthropic’s own claude.ai domain to distribute the SectopRAT information-stealing Trojan, compromising at least 29 organisations in the space of two days. The campaign, which Huntress has named FakeAgent, ran between 21 and 22 July 2026. Victims searching for >>Claude Desktop The post FakeAgent Campaign: Malicious Claude Artifact Used to Distribute SectopRAT to 29 Organisations appeared first on IT Security Guru.
First seen on itsecurityguru.org
Jump to article: www.itsecurityguru.org/2026/07/23/fakeagent-campaign-malicious-claude-artifact-used-to-distribute-sectoprat-to-29-organisations
![]()

