A malvertising campaign on Bing is reportedly using ads for a fake Claude desktop app to spread SectopRAT malware. The activity stands out because the installer is said to be hosted on a legitimate Claude.ai domain, which could make the download appear trustworthy to users searching for Anthropic’s AI assistant.
The core tactic appears to be search ad abuse. People looking for Claude may encounter a sponsored result that looks legitimate, click through, and download what seems to be an official desktop application. Instead of a normal install, the file reportedly delivers SectopRAT, a remote access trojan that can give attackers a foothold on a victim’s system.
Using a real Claude.ai domain adds an extra layer of deception to the campaign. Security threats tied to well-known brands often rely on fake websites, but in this case the trusted domain reference could lower suspicion and increase the chances that users proceed with the download.
The report highlights another example of how search advertising can be weaponized to distribute malware through convincing software lures. For users and organizations, the incident is a reminder that even familiar brand names and seemingly valid links can still be part of a malware delivery chain when threat actors abuse online ad platforms.