#FakeAgent
*If your "AI agent" isn't an AI or an agent, but it looks and acts like an agent, is that good enough? #fakeagent

"Gartner estimates only about 130 of the thousands of agentic AI vendors are real."

www.gartner.com/en/newsroom/...
Gartner: Over 40% of Agentic AI Projects Will Be Canceled by End 2027
Over 40% of agentic AI projects will be canceled by the end of 2027, due to escalating costs, unclear business value or inadequate risk controls, according to Gartner.
www.gartner.com
July 8, 2025 at 10:10 AM
FakeAgent HD Two girls make me cum quick part 1
www.adultvideo.info
September 19, 2026 at 7:15 PM
Fake Claude Desktop Campaign Turns Anthropic’s Trusted AI Domain Into a Malware Trap: How FakeAgent Delivered SectopRAT to Organizations Worldwide

Introduction: When Trust Becomes the Weapon Artificial intelligence platforms have quickly become some of the most trusted destinations on the…
Fake Claude Desktop Campaign Turns Anthropic’s Trusted AI Domain Into a Malware Trap: How FakeAgent Delivered SectopRAT to Organizations Worldwide
Introduction: When Trust Becomes the Weapon Artificial intelligence platforms have quickly become some of the most trusted destinations on the internet. Millions of users now rely on AI assistants for productivity, coding, research, and business operations. But as AI adoption accelerates, cybercriminals are discovering a dangerous opportunity: abusing the trust users place in legitimate AI brands. A new campaign investigated by Huntress reveals how attackers transformed Anthropic’s legitimate Claude ecosystem into a delivery mechanism for malware.
undercodenews.com
July 23, 2026 at 11:46 AM
FakeAgent, MacSync, and AMOS Distribution via Legitimate AI Sharing Pages
## 1. Basic Information * Original Title: How threat actors are turning trusted AI platforms into an attack surface * Source: BleepingComputer, Huntress * Publication Date: 2026-09-11 * Severity: High * Basis for Severity: Trusted AI sharing pages are being used to distribute malware via ads and SEO, and infections have been confirmed across multiple organizations. This technique abuses the trust placed in public pages. * Original Article: How threat actors are turning trusted AI platforms into an attack surface * Related Sources: Huntress: FakeAgent malvertising, Huntress: MacSync stealer and RAT, Huntress: What is AI poisoning?, Huntress: AMOS AI sharing chat abuse, MITRE ATT&CK: Malicious Copy and Paste * Related Malware: FakeAgent, SectopRAT, MacSync, AMOS * Related Products: Claude Artifacts, Claude Share, ChatGPT shared conversations, Grok shared conversations, macOS, Windows ## 2. Executive Summary Threat actors use Claude Artifacts/Share and ChatGPT/Grok shared pages to direct users to execute fake apps or paste commands into the Terminal. FakeAgent delivering SectopRAT, MacSync, and AMOS represent distinct attack scenarios. ## 3. Attack Flow ### Flow 1: FakeAgent: Delivering SectopRAT to Windows 1. Sponsored ads on Bing direct users to a legitimate Claude Artifact. 2. A download link inside the Claude Artifact directs users to an external fake Claude Desktop distribution site. 3. The user executes `ClaudeDesktop.exe`. 4. The malware launches SectopRAT through DLL side-loading using a signed helper, scheduled tasks, virtual environment detection, and EtherHiding. 5. SectopRAT provides remote access capabilities. ### Flow 2: MacSync: macOS Infection via Claude Shared Conversations 1. Sponsored ads on Google direct users to fake Apple Support instructions on Claude Share. 2. The user opens the Terminal, pastes the provided curl command, and executes it. 3. A six-stage framework deploys a loader, an information-stealing feature via AppleScript, and a Mach-O format RAT. 4. The malware collects browser cookies and credentials, the Keychain, SSH and cloud authentication keys, and wallet-related data. 5. It also uses a signed helper to obtain screen recording permissions and a modified wallet app to steal recovery phrases. ### Flow 3: AMOS: Fake Disk Cleanup Instructions on ChatGPT and Grok 1. Shared ChatGPT and Grok conversations appearing in search results mimic instructions to free up macOS disk space. 2. The user pastes and executes a command in the Terminal to retrieve a loader. 3. Credentials obtained through a fake password prompt are verified and used for privilege escalation and data theft. 4. AMOS collects and exfiltrates browser, Keychain, and wallet data, and replaces certain wallet applications with modified versions. 5. A LaunchDaemon and monitoring script restart the info-stealer to maintain persistence. ## 4. Attacker Position and Execution Location * External threat actors direct users via ads, search results, and public AI sharing pages. * Once executed, the RAT/info-stealing malware runs on the victim endpoint to access credentials and wallets. ## 5. Victim and Administrator Perspective ### Victims * Pages disguised as Claude Desktop, Apple Support, or macOS disk cleanup, along with requests to paste commands into the Terminal. * Fake applications and unexpected requests for Full Disk Access or screen recording. ### Administrators * Terminal and shell execution triggered by user actions, suspicious curl traffic, unknown executables, DLL side-loading, and scheduled tasks. The parent of the shell is not necessarily the browser. * New external domains visited immediately after accessing legitimate AI domains, along with data access to wallets, Keychains, and browsers. ## 6. Success and Failure Conditions ### Success Conditions * Users trust the ad/SEO results and the legitimate AI sharing pages. * Users execute external downloads or shell commands via the clipboard. * Application control or EDR does not block multi-stage loaders, side-loading, or credential access. ### Failure Conditions * Inference: Inspecting redirects and downloads from sharing pages, and blocking them if identified as malicious. * Inference: Controlling unauthorized script execution on the endpoint and addressing pathways where users paste commands from sharing pages. Restricting only browser child processes does not prevent this entire pathway. * Inference: Blocking unauthorized DLL loading, persistence, and credential access via application control or EDR limits subsequent damage. ## 7. What Happens Upon Success * RAT infection and remote control of Windows/macOS endpoints. * Theft of browser cookies and credentials, Keychains, SSH and cloud authentication keys, and wallet-related information. * Inference: If stolen sessions or keys are valid, this can lead to unauthorized access to SaaS and cloud environments or cryptocurrency theft. ## 8. Observable Logs ### Email * None. The primary vector is search ads and SEO. ### Proxy / SWG / DNS * Inference: Transitions from legitimate AI sharing URLs to newly registered or lookalike download domains, payload traffic, C2, and blockchain RPC traffic. ### Endpoint / EDR * Inference: Depending on the scope of EDR collection, logs may show user-initiated shells, curl commands, DLL loading, scheduled tasks, and access to credential files. Direct parent-child relationships between browsers and shells are not assumed. ### Identity / IdP * Inference: Use of stolen cookies, cloud auth keys, or SSH keys from unknown sources. ### SaaS / Cloud * Inference: If stolen tokens are abused, review SaaS and cloud operation logs to identify the source and targets. Investigate AI sharing page browsing paths using available browser history or proxy logs. ### Network * Inference: C2 traffic for SectopRAT, MacSync, and AMOS, referencing contracts used in EtherHiding, and unusual bulk exfiltration of credentials. ## 9. Attack Success Determination Below are ranges confirmed by public information and criteria used for internal investigations. * **User Action Confirmed** : Public Info: Huntress reports user execution of commands in the fake Claude Desktop execution, as well as the MacSync and AMOS cases. Do not treat three separate cases as consecutive actions by a single victim. * **Malware Execution or Authentication Success Confirmed** : Public Info: SectopRAT infection via FakeAgent, MacSync info-stealer features and RAT, and AMOS execution and persistence are reported respectively. * **Data Theft or Session Compromise Confirmed** : Public Info: Huntress reports information theft and analyzes the collection targets of each malware. This does not mean all sensitive data was stolen from every victim endpoint. * **Subsequent Compromise Confirmed** : Criteria: Confirmed when unauthorized use of stolen sessions or auth keys, or unauthorized fund transfers are identified. Public sources do not determine the full scope of these successes. ## 10. Investigation Playbook ### Triggers * External downloads after visiting AI sharing pages, user execution of suspicious shell commands, or execution of unknown applications. ### Initial Triage * Preserve search terms, ads, AI sharing URLs, redirect chains, hashes of downloaded files, and executed commands. ### Endpoints and Servers * For Windows, check for DLL side-loading, scheduled tasks, and RATs. For macOS, check shell history, quarantine attributes, LaunchAgents/LaunchDaemons, AppleScript, TCC, and modified wallet apps. ### Authentication and Cloud * Check browser sessions, SSH/cloud auth keys, Telegram, wallets, and IdPs for usage from unknown sources and token creation. ### Subsequent Actions * Check for reuse of stolen cookies, cloud API enumeration, wallet transfers, and additional RATs or remote management tools. ### Containment * Isolate the endpoint to preserve evidence, and revoke browser and IdP sessions as well as exposed tokens. Reissue SSH and cloud auth keys, and if wallet recovery information is exposed, consider migrating assets to a new wallet created on a secure device. * Add malicious sharing URLs, redirect domains, and hashes to organizational blocklists. ### Judgment Categories * Distinguish between page views, user execution, loader success, RAT/info-stealer C2, sensitive data theft, and subsequent abuse. ## 11. Defense and Detection Ideas ### Single Events * Inference: Treat suspicious download and execution commands run by users in the Terminal, PowerShell, or cmd as detection candidates. Do not require them to be child processes of the browser. * Inference: Monitor signed helpers loading unknown DLLs from the same directory, taking file provenance into account. ### Time-Series Correlation * Inference: Correlate search ads, AI sharing pages, access to external destinations, and subsequent shell execution, credential access, and C2 traffic for the same endpoint and user over time. ### Threat Hunting * Inference: Cross-search for commands executed before and after viewing AI sharing URLs, downloads, DNS activity, and credential access. 30 minutes is an initial search window example; expand this based on execution delays or log retention periods. ### Log Gaps * Lack of full URLs, redirects, clipboard data, process parent-child relationships, or TCC history may make it difficult to separate legitimate AI usage from attack paths. ### Priority Mitigations * Inference: Prioritize correlating page views with manual shell execution, application control, inspecting external redirect destinations, and credential revocation procedures. ## 12. Facts / Inference / Hypothesis ### Facts * In the FakeAgent campaign, sponsored Bing ads directed users to a legitimate Claude Artifact, which led to a fake Claude Desktop distribution domain that deployed SectopRAT. Huntress confirmed activity across at least 29 organizations. * FakeAgent combined DLL side-loading using a signed `jcef_helper.exe` and a modified `libcef.dll`, scheduled tasks named `DockerDesktop.exe`, VMProtect, GPU-based virtual environment detection, and EtherHiding using BSC smart contracts. * In the MacSync campaign, Google sponsored ads directed users to fake Apple Support instructions on `claude.ai/share`, prompting them to run Terminal commands containing `curl`, which deployed a six-stage loader, an AppleScript info-stealer, and a Mach-O RAT. * Huntress reported that MacSync collects browser cookies and credentials, Keychains, Telegram data, SSH and cloud auth keys, and wallet-related info, while also using a signed helper for screen recording permissions. * Huntress reported a December 2025 AMOS case where ChatGPT and Grok shared conversations appearing in search results disguised themselves as disk cleanup instructions to trick users into pasting and executing commands. * Public information does not indicate infrastructure compromise of AI vendors; trust in legitimate hosts and brands was abused. ### Inference * Relying solely on URL reputation data that permits `claude.ai` broadly may overlook malicious content hosted on legitimate sites and external redirects. * Search ads, AI sharing pages, the clipboard, and script execution must be correlated as a single path. ### Hypothesis No additional hypotheses. Unverified items are listed under 'Unknowns and Further Investigation'. ## 13. MITRE ATT&CK Mapping * **T1189 Drive-by Compromise** (Confidence: high): Directing users from ads and SEO results to legitimate AI sharing pages and malicious sites. * **T1204.002 User Execution: Malicious File** (Confidence: high): In FakeAgent, users execute an installer distributed as a fake Claude Desktop. * **T1204.004 User Execution: Malicious Copy and Paste** (Confidence: high): In MacSync and AMOS distribution paths, users are tricked into pasting and executing commands in the Terminal. * **T1574.002 Hijack Execution Flow: DLL Side-Loading** (Confidence: high): FakeAgent combines a signed helper with a modified libcef.dll. * **T1053.005 Scheduled Task/Job: Scheduled Task** (Confidence: high): Creates a scheduled task disguised as `DockerDesktop.exe` on Windows. * **T1555.003 Credentials from Password Stores: Credentials from Web Browsers** (Confidence: high): MacSync and AMOS collect browser cookies and credentials. ## 14. Unknowns and Further Investigation * A complete list of malicious Claude Artifact/Share and ChatGPT/Grok shared URLs. * Attribution of ad accounts and campaign operators. * Lifespan and evolution of all C2 servers, contracts, and payload hashes for FakeAgent. * It remains unverified whether multiple campaign operators are the same or if they automate the creation of AI sharing pages. ## 15. Impact on SOCs and Organizations For organizations where users can view AI sharing pages during business hours, verify not only whether the domain is legitimate, but also subsequent external downloads or user-executed commands. Because manually opened Terminals do not always run as child processes of the browser, it is useful to correlate the activities of the same endpoint and user across a timeline. ## 16. Summary by Role * **SOC** : Correlate search ads -> AI sharing pages -> external domains -> downloads/Terminal execution -> credential access in chronological order. * **Administrators** : Avoid blanket permissions for AI sharing pages and implement application allowlisting, script execution controls, and correlation monitoring between browser browsing and shell execution. * **Users** : Do not blindly execute downloads or Terminal commands suggested by search ads or AI responses; verify official distribution sources and administrative procedures.
dev.to
September 12, 2026 at 1:33 AM
Claude・ChatGPT・Grokの正規ドメインがマルウェア配布の入口に AI共有機能を悪用したサイバー攻撃|セキュリティニュースのセキュリティ対策Lab

HuntressはClaude ArtifactsやClaude・ChatGPT・Grokの共有機能を悪用したマルウェア配布を報告しました。FakeAgentでは正規claude.aiドメインから ...
rocket-boys.co.jp/security-mea...
Claude・ChatGPT・Grokの正規ドメインがマルウェア配布の入口に AI共有機能を悪用したサイバー攻撃|セキュリティニュースのセキュリティ対策Lab
HuntressはClaude ArtifactsやClaude・ChatGPT・Grokの共有機能を悪用したマルウェア配布を報告しました。FakeAgentでは正規claude.aiドメインから少なくとも29組織へSectopRATを配布。MacSync、AMOS事例と企業が見直すべきAI共有コンテンツの対策を整理
rocket-boys.co.jp
September 15, 2026 at 3:40 AM
FakeAgent es un malware diseñado para infiltrarse en sistemas a través de plataformas de IA confiables.

https://norvik.tech/news/analisis-fakeagent-macsync-amos-distribution
September 12, 2026 at 5:05 AM
Attackers are abusing trusted AI platforms like Claude, ChatGPT, and Grok to deliver fake downloads and malicious commands. Campaigns such as FakeAgent show how search poisoning and platform trust can fuel malware delivery. #Claude #ChatGPT #Grok
How Threat Actors Are Turning Trusted AI Platforms Into An Attack Surface
Attackers are abusing trusted AI platform features like Claude Artifacts, claude.ai/share links, ChatGPT, and Grok conversations to lure victims into downloading malware or running malicious commands. Huntress says campaigns such as FakeAgent, MacSync, and AMOS show how search poisoning and platform trust can be weaponized against users, even on real domains. #Claude #ChatGPT #Grok #FakeAgent #SectopRAT #MacSync #AMOS #Anthropic #Huntress
www.hendryadrian.com
September 11, 2026 at 5:00 PM
Claude sessions being stolen via Vidar, RedLine & FakeAgent—sessions, cookies, not passwords. #AI #Security #Infostealer #Claude #Malware #Cybersecurity https://thedailytechfeed.com/infostealer-malware-hijacks-claude-sessions-bypassing-2fa/
August 31, 2026 at 2:55 AM
A fake Claude Desktop installer sideloads SectopRAT while infostealers hijack sessions to skip MFA. https://intel.threadlinqs.com/threat/TL-2026-2249 #ThreatIntel #SectopRAT #Vidar #LummaC2
August 31, 2026 at 3:23 AM
Cybercriminelen misbruiken AI-platform Anthropic Claude voor diefstal van inlogg

Het Anthropic Claude AI-platform is een doelwit geworden voor cybercriminelen, die diverse aanvalsstrategieën inzetten om inloggegevens te stelen, betaald gebruik te kapen en apparaten opnieuw te infecteren. Ee...
Cybercriminelen misbruiken AI-platform Anthropic Claude voor diefstal van inloggegevens en fraude.
Het Anthropic Claude AI-platform is een doelwit geworden voor cybercriminelen, die diverse aanvalsstrategieën inzetten om inloggegevens te stelen, betaald gebruik te kapen en apparaten opnieuw te infecteren. Een methode, door beveiligingsbedrijf Huntress gedoopt FakeAgent, misbruikt de infrastructuur van Claude zelf. Tussen 21 en 22 juli 2026 werden gebruikers die via Bing zochten naar de Claude desktop app misleidende gesponsorde advertenties getoond. Deze advertenties leidden naar een schadelijke, publieke Claude Artifact op het legitieme claude.ai domein. Een klik op de valse installer, vermomd als ClaudeDesktop.exe, activeerde DLL sideloading met een aangepaste libcef.dll, wat resultee...
newsfacts.info
August 31, 2026 at 3:00 AM
FakeAgent HD Two girls make me cum quick part 2
www.adultvideo.info
August 26, 2026 at 7:10 PM
Inside FakeAgent: How a Claude Desktop Malvertising Campaign Hit 29 Organizations with SectopRAT
Inside FakeAgent: How a Claude Desktop Malvertising Campaign Hit 29 Organizations with SectopRAT
www.huntress.com
July 27, 2026 at 1:54 PM
FakeAgent Campaign uses Malicious Bing Ads and Claude.ai Artifacts to Infect Corporate Users:

cybersecuritynews.com/fakeagent-ca...
July 27, 2026 at 6:09 AM
FakeAgent Campaign Uses Malicious Bing Ads and Claude.ai Artifacts to Infect Corporate Users

A dangerous new malware campaign is tricking corporate workers who simply want a desktop version of a popular AI assistant. Between July 21 and July 22, 2026, at least 29 organizations saw unusual software…
FakeAgent Campaign Uses Malicious Bing Ads and Claude.ai Artifacts to Infect Corporate Users
A dangerous new malware campaign is tricking corporate workers who simply want a desktop version of a popular AI assistant. Between July 21 and July 22, 2026, at least 29 organizations saw unusual software installs and hidden persistence on their systems after staff searched for the Claude desktop app. The attack begins with paid ads [...] The post FakeAgent Campaign Uses Malicious Bing Ads and Claude.ai Artifacts to Infect Corporate Users appeared first on Cyber Security News .
news-area.com
July 24, 2026 at 11:58 PM
FakeAgent Campaign Uses Malicious Bing Ads and Claude.ai Artifacts to Infect Corporate Users

potatosecuritynews.com/fakeagent-ca...

#Potatosecurity #Tietomurto
July 24, 2026 at 1:01 PM
FakeAgent: How Hackers Hid Malware Inside a Real Claude.ai Link www.wangdoo.com/fakeagent-ho...
July 24, 2026 at 10:34 AM
FakeAgent Campaign Uses Malicious Bing Ads and Claude.ai Artifacts to Infect Corporate Users

cybersecuritynews.com/fakeagent-ca...

#Cybersecurity #Tietomurto
Claude
Claude is Anthropic's AI, built for problem solvers. Tackle complex challenges, analyze data, write code, and think through your hardest work.
Claude.ai
July 24, 2026 at 12:40 PM
A fake Claude Desktop installer served off real claude.ai side-loads SectopRAT and hides C2 on the blockchain. https://intel.threadlinqs.com/threat/TL-2026-1669 #ThreatIntel #SectopRAT #Arechclient2 #Stealc
July 24, 2026 at 1:41 PM
FakeAgent Campaign Uses Malicious Bing Ads and Claude.ai Artifacts to Infect Corporate Users
FakeAgent Campaign Uses Malicious Bing Ads and Claude.ai Artifacts to Infect Corporate Users
A dangerous new malware campaign is tricking corporate workers who simply want a desktop version of a popular AI assistant. Between July 21 and July 22, 2026, at least 29 organizations saw unusual software installs and hidden persistence on their systems after staff searched for the Claude desktop app. The attack begins with paid ads on Microsoft Bing. When someone types a normal query for the app, sponsored results appear that look trustworthy. One of those ads even points to the real Claude.ai website, which lowers suspicion and makes the trap harder to spot. Analysts from Huntress identified the activity after their security operations center flagged waves of odd executable installs, Defender exclusions, and strange scheduled tasks tied to a file named ClaudeDesktop.exe. Huntress said in a report shared with Cyber Security News (CSN) that the campaign, which they call FakeAgent, funnels victims through a malicious public Claude Artifact and ultimately delivers SectopRAT, a remote access trojan that steals credit cards, passwords, browser data, and personal files. Before Anthropic removed the bad Artifact, it had already drawn about 7,100 page views. That volume shows how quickly paid search ads and trusted domains can combine to reach busy office users who only meant to install helpful software. The campaign also used heavy anti-analysis tricks, including packing and graphics hardware checks that try to spot virtual machines. Those steps slow down defenders and let the malware stay quiet longer on real corporate machines. FakeAgent Campaign Uses Malicious Bing Ads The infection chain starts with a simple Bing search for “CLAUDE DESKTOP APP.” Sponsored results fill the top of the page with lookalike download sites, a pattern also seen in earlier  weaponized PuTTY Bing ads  that abused the same search ads model. Bing search results with several malicious sponsored advertisements (Source – Huntress) Mixed among them sits a sponsored link that lands on the legitimate Claude.ai domain, specifically a public Artifact page. Public Artifacts are user-generated pages that anyone can share. Claude itself warns that the content is unverified, yet many people still trust anything hosted on the official domain. Claude Desktop – Cowork phishing page hosted as a Claude artifact (Source – Huntress) Clicking Download on the fake page sends the user first to claude.ai.download-app.us and then to downloading-api.it.com, where ClaudeDesktop.exe is offered. Figure 1 in the Huntress material shows the Bing results packed with those sponsored traps. Figure 2 shows the Artifact page dressed up as a normal Claude Desktop installer. Because the journey began on a real Claude.ai address, many users ran the file without a second thought. ClaudeDesktop.exe is not the real app. It is a renamed, signed JetBrains helper that loads a tampered library beside it, a classic  DLL sideloading malware attack  that lets malicious code run under a trusted process name. An identical copy called DockerDesktop.exe is later written as a scheduled task so the infection can restart after reboot. A second signed program, sslconf.exe, appears under an EdgeUpdate folder and loads yet another altered library. That stage checks graphics hardware and video memory to avoid sandboxes, then decrypts a hidden payload with a graphics shader instead of ordinary CPU code. The final result is SectopRAT, which hunts browser logins, cookies, autofill data, credit cards, and messaging apps. Command addresses are not hard-coded in plain text. They are pulled from Ethereum blockchain contracts, a method known as EtherHiding that lets operators change servers by posting new transactions that are hard to take down. How Corporate Users Get Infected Corporate staff often search for AI desktop tools during work hours and click the first convenient result. That habit turns everyday research into a direct path for malware when ads and trusted domains are abused together. Similar tricks have already appeared in  shared Claude chats malware  campaigns that also rode the Claude brand to look real. Once inside, SectopRAT gives attackers remote control and a steady stream of stolen credentials and files. Persistence through scheduled tasks and Defender exclusions keeps the foothold alive even after a reboot or a basic cleanup attempt. Huntress linked the same operator style to earlier fake Docker Desktop lures, showing this is not a one-off experiment. Deobfuscated LLM representation of embedded .NET code (Source – Huntress) Defenders should treat top-level domains with caution and never assume a familiar brand name equals a safe download. Users should type official vendor addresses directly instead of trusting sponsored search results, and security teams should watch for unexpected ClaudeDesktop.exe or DockerDesktop.exe activity, new EdgeUpdate paths, and odd scheduled tasks. Clear  remote access Trojan practices  still matter: keep software updated, limit unnecessary admin rights, and verify every installer against the vendor’s own site. Huntress reported the malicious Artifact to Anthropic, and it was removed. The episode still underlines a wider lesson. As more people chase AI tools, both search ads and AI hosting features become attractive stages for malware that looks legitimate until it is far too late. Indicators of compromise (IoCs):- Type Indicator Description URL claude.ai/public/artifacts/ca456f1f-44c0-42af-b329-4f1c7534a877 Malicious Claude Desktop download Artifact page Domain download-app.us Redirect domain for ClaudeDesktop.exe Domain claude.ai.download-app.us Attacker-controlled download redirect host URL downloading-api.it.com/html/claude/win Path serving the malicious executable Domain 5ca8758c-02d0-4a72-89c8-d468b66dda41.com Backup SectopRAT domain IP Address 2.24.131.246 Active SectopRAT command-and-control server IP Address 107.189.24.67 Historical C2 address (2025-05-30) IP Address 104.194.133.210 Historical C2 address (2025-07-13) IP Address 107.189.26.86 Historical C2 address (2025-07-26) IP Address 107.189.21.86 Historical C2 address (2025-08-11) IP Address 45.59.124.17 Historical C2 address (2025-08-22) IP Address 45.59.125.228 Historical C2 address (2025-09-05) IP Address 45.59.122.82 Historical C2 address (2025-09-14) IP Address 107.189.17.143 Historical C2 address (2025-09-24) IP Address 45.59.122.134 Historical C2 address (2025-11-23) IP Address 45.59.122.235 Historical C2 address (2025-12-03) IP Address 107.189.22.118 Historical C2 address (2025-12-09) IP Address 107.189.20.32 Historical C2 address (2025-12-16) IP Address 107.189.20.95 Historical C2 address (2025-12-29) IP Address 107.189.24.255 Historical C2 address (2026-01-10) IP Address 45.59.117.145 Historical C2 address (2026-01-28) IP Address 45.59.114.190 Historical C2 address (2026-03-13) IP Address 45.59.123.122 Historical C2 address (2026-04-03) IP Address 45.59.117.67 Historical C2 address (2026-04-14) IP Address 195.110.58.222 Historical C2 address (2026-04-20) IP Address 191.101.80.211 Historical C2 address (2026-05-12) Blockchain 0xe012d0f34cde9b870e9d9ed566ea5f8fd9b92228 SectopRAT BSC contract Blockchain 0xc1907d7be91f95903ad66d775c397302e7dd9228 libcef.dll stager BSC contract SHA256 1cd58cfba596da296ab1878d74023e00c399345a1b6c2a0e5446c53563f4e3bb tempdir.dll SHA256 26bae4d7012bf59847ab4036a065419c3d4ca47e020479f55b3b2c6d0d21394a libcef.dll SHA256 1fe3646d27d286db8123297e06ae7badf3e26f352a04f91b6d82c28869a91664 Embedded SectopRAT payload SHA256 f8acb8f5cf88b77a4c27d7fd6856aa299bb178e85f9963c2fbd447d818da3ed0 DockerDesktop.exe / ClaudeDesktop.exe (benign host binary) SHA256 fd826215add30c1319eefa291b6eaf8ddfa7720cfe816c49aef6fe8a88de7939 SSLConf.exe (benign host binary) File Name ClaudeDesktop.exe Initial malicious downloader staged as Claude app File Name DockerDesktop.exe Persistent scheduled-task copy of the loader File Name libcef.dll Tampered DLL used for sideloading File Name tempdir.dll Second-stage sideloaded malicious DLL File Name sslconf.exe Signed IBM SPSS binary used for further sideloading File Name appcfg.dat Encrypted on-disk payload container Note:   IP addresses and domains are intentionally defanged (e.g.,  [.] ) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM . ALERT!: 20+ government sites delivered malware to businesses and citizens. See full attack research to check your own exposure. The post FakeAgent Campaign Uses Malicious Bing Ads and Claude.ai Artifacts to Infect Corporate Users appeared first on Cyber Security News .
cybersecuritynews.com
July 24, 2026 at 12:13 PM