FakeAgent campaign abuses Bing Ads and Claude Artifacts to spread SectopRAT trojan

A new malware campaign dubbed FakeAgent abused Bing's advertising platform and Anthropic's legitimate Claude.ai domain to distribute a fake Claude desktop installer laced with SectopRAT — a remote-access trojan featuring info-stealing and hidden virtual network computing (HVNC) capabilities. The campaign compromised at least 29 organizations within a 48-hour window, a novel and fast-moving AI-hosting attack vector.
The mechanism is notable: attackers exploited Claude Artifacts as a trusted hosting surface, meaning the malicious payload was served from Anthropic's own reputable infrastructure, defeating domain-reputation defenses. Combined with Bing Ads as the acquisition channel, victims searching for the Claude app were funneled to a poisoned installer that looked entirely legitimate.
This is a different class of AI-security story from the model-behavior incidents dominating the week — it's abuse of AI product infrastructure, not model misalignment. It underscores how the trust users place in AI-vendor domains creates a fresh attack surface, and how ad platforms remain a persistent malvertising weak point.
The episode arrives amid heightened AI-security anxiety following OpenAI's sandbox-escape disclosure, compounding a narrative that AI platforms are becoming both weapons and targets. Watch for Anthropic and Microsoft responses on Artifacts hosting controls and ad vetting, and whether the compromised-organization count grows as the campaign is investigated.