Malicious Bing Ads and Claude.ai Artifacts

Overview

Security analysts have uncovered a malware campaign dubbed FakeAgent that exploits malicious Bing ads and Claude.ai public Artifacts to trick corporate users into downloading a fake Claude desktop app. Instead of productivity, victims receive SectopRAT, a remote access trojan capable of stealing credentials, credit cards, browser data, and personal files.

Infection Chain

The attack begins with a Bing search for “Claude Desktop App.”

  • Sponsored results include lookalike download sites and even links to the legitimate Claude.ai domain.
  • One malicious Artifact page masqueraded as a Claude Desktop installer, drawing over 7,100 views before removal.
  • Clicking “Download” redirected users through attacker‑controlled domains (claude.ai.download-app.us, downloading-api.it.com) to deliver ClaudeDesktop.exe.

The executable is a signed JetBrains helper abused via DLL sideloading. Persistence is achieved by:

  • Dropping a copy named DockerDesktop.exe as a scheduled task.
  • Deploying sslconf.exe under an EdgeUpdate folder with another tampered DLL.
  • Using graphics hardware checks and shader‑based decryption to evade sandboxes.

The final payload, SectopRAT, provides attackers with remote control and continuous data theft.

Advanced Evasion Techniques

  • DLL sideloading under trusted process names.
  • Scheduled tasks to survive reboots.
  • Defender exclusions to bypass antivirus.
  • Graphics shader decryption to hide payloads from CPU‑based analysis.
  • EtherHiding — command‑and‑control servers pulled dynamically from Ethereum blockchain contracts, making takedowns difficult.

Indicators of Compromise (IoCs)

Key artifacts linked to FakeAgent include:

  • Malicious Artifact URL: claude.ai/public/artifacts/ca456f1f-44c0-42af-b329-4f1c7534a877
  • Domains: download-app.us, claude.ai.download-app.us, downloading-api.it.com
  • C2 IPs: 2.24.131.246 (active), plus historical addresses like 107.189.24.67, 45.59.124.17
  • Blockchain contracts: 0xe012d0f34cde9b870e9d9ed566ea5f8fd9b92228 (SectopRAT)
  • Files: ClaudeDesktop.exe, DockerDesktop.exe, libcef.dll, tempdir.dll, sslconf.exe

Defensive Recommendations

Organizations should:

  • Avoid sponsored search results — type vendor URLs directly.
  • Verify installers against official sources.
  • Monitor for suspicious executables like ClaudeDesktop.exe or DockerDesktop.exe.
  • Check EdgeUpdate paths for unexpected binaries.
  • Harden endpoints with EDR capable of detecting RAT persistence.
  • Educate staff on the risks of downloading AI tools from unverified sources.

Expert in the Cloud Insight

FakeAgent shows how attackers weaponize search ads and trusted domains to reach busy office users. By combining malicious Bing ads with Claude.ai Artifacts, they created a convincing lure that bypassed user skepticism. The lesson is clear: brand familiarity does not equal safety. Enterprises must enforce strict download policies, monitor for IoCs, and treat AI‑related downloads as high‑risk vectors.

Be the first to comment

Leave a Reply

Your email address will not be published.


*


This site uses Akismet to reduce spam. Learn how your comment data is processed.