Fake Claude app pushed via Bing ads drops SectopRAT malware

A malvertising campaign on Bing promotes a fake Claude desktop app installer that delivers the dangerous SectopRAT malware. Stay safe.

viernes, 24 de julio de 2026 • 4 min read • Q2BSTUDIO Team

Campaña de malvertising con Claude falso en Bing

In recent days, the cybersecurity community has detected a malvertising campaign that exploits Bing’s advertising service to promote a fake desktop application for Claude, Anthropic’s AI assistant. The link leads to a site mimicking the legitimate Claude.ai domain but actually downloads a malicious installer that deploys the SectopRAT remote access trojan. This threat poses a significant risk to both individual users and business environments, especially those integrating AI tools into their workflows.

The technique used is not new, but it is particularly dangerous because it combines trust in well-known advertising platforms with the growing popularity of artificial intelligence assistants. SectopRAT is a sophisticated malware capable of taking full control of the infected computer, stealing credentials, capturing keystrokes, accessing the camera and microphone, and exfiltrating sensitive data. Once inside a corporate network, it can serve as a gateway for broader attacks, such as ransomware or lateral movement toward critical servers.

From a technical perspective, the campaign exploits trust in search ads. The attackers purchase ad slots on Bing so that their link appears before the official site when users search for “Claude desktop app” or similar terms. The fake domain is hosted on a subdomain that uses a valid SSL certificate, adding a layer of legitimacy. The installer, once executed, deploys SectopRAT using obfuscation and anti-detection techniques that evade most traditional antivirus software. Additionally, the malware uses encrypted connections to communicate with its command-and-control server, making tracking difficult.

For companies that are adopting artificial intelligence solutions, such as productivity tools based on Claude or ChatGPT, this kind of campaign underscores the need to be extremely vigilant. It is not enough to trust a platform’s reputation; it is essential to verify URLs, download software only from official sources, and keep security solutions up to date. In this context, having a comprehensive cybersecurity approach becomes a strategic priority.

At Q2BSTUDIO, as a company specializing in software development and technology, we understand that innovation must go hand-in-hand with protection. That is why we offer cybersecurity services that include vulnerability audits, continuous pentesting, and design of secure architectures for cloud applications. Our team integrates security practices from the development phase, following DevSecOps methodologies, to ensure that both custom software and AI-based solutions are resilient against threats like SectopRAT.

This campaign also highlights the importance of artificial intelligence applied to defense. Machine learning-based detection systems can identify anomalous patterns in network traffic or process behavior, alerting to potential infections before they cause damage. At Q2BSTUDIO we develop AI agents and automation solutions that not only improve business productivity but also strengthen security posture through proactive monitoring and automated incident response.

In addition to cybersecurity and AI, our expertise covers cloud computing with AWS and Azure, business intelligence with Power BI, and multiplatform application development. For example, a company migrating its infrastructure to the cloud can benefit from a personalized risk analysis and the implementation of access controls based on Zero Trust policies. Likewise, integrating BI systems allows real-time visualization of security indicators, facilitating informed decision-making.

For end users, the main recommendation is to distrust sponsored ads that promise direct downloads of popular software. It is always safer to access the official site by typing the URL directly into the browser or using saved bookmarks. In the case of Claude, the official desktop app is only distributed through claude.ai/download, not via third-party ads. Companies, on the other hand, should implement application restriction policies, continuous employee training, and perimeter security solutions such as next-generation firewalls or EDR (Endpoint Detection and Response).

The SectopRAT malware is not new, but its distribution through malvertising on Bing represents an evolution in cybercriminal tactics. By leveraging trust in the legitimate advertising ecosystem, they manage to bypass many security filters. Early detection of this campaign by independent researchers has allowed rapid response teams to take action, but the threat persists as long as malicious ads continue to appear on platforms.

In conclusion, the fake Claude app on Bing ads is a reminder that cybersecurity must be an essential component of any digital transformation strategy. At Q2BSTUDIO we advocate for a holistic approach that combines custom software development, artificial intelligence, cloud, and BI to build robust and secure systems. Protection against threats like SectopRAT requires not only technical tools but also a security culture that permeates all levels of the organization. If your company is looking to implement AI solutions or needs to strengthen its cybersecurity posture, our team is ready to accompany you at every step of the process.

A BREAK?

Play for a moment before you go

OUR SERVICES

How we can help you

Do you have a project in mind?

Tell us your vision and we'll turn it into a software solution. Whatever the scope, we make your idea real.