By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Fake Claude App on Bing Ads Delivers SectopRAT Malware
A malvertising campaign is actively distributing a fake Claude desktop application installer through advertisements on the Bing search engine. This campaign leverages a legitimate Claude.ai domain to host the malicious installer, aiming to deceive users into downloading and executing malware. The primary payload delivered by this fake application is the SectopRAT malware, a remote access trojan known for its ability to grant attackers extensive control over compromised systems.
The campaign was identified by researchers who observed advertisements on Bing promoting a "Claude AI" desktop application. Upon clicking these ads, users were directed to a webpage that appeared to be an official download portal for the Claude AI desktop client. However, the downloaded installer contained the SectopRAT malware. This tactic of using legitimate domains for hosting malicious files, known as domain fronting or typosquatting, is a common technique used by threat actors to bypass security measures and gain user trust.
SectopRAT is a sophisticated piece of malware that allows attackers to perform a wide range of malicious activities. These include unauthorized access to files, keystroke logging, screen recording, and the execution of arbitrary commands on the victim's machine. The deployment of SectopRAT through a seemingly legitimate application installer highlights the evolving sophistication of cyber threats targeting unsuspecting users. The use of Bing ads as an initial vector suggests a broad reach for this attack, potentially impacting a large number of users who rely on the search engine for software discovery.
Security experts are advising users to exercise extreme caution when downloading software, especially from search engine advertisements. It is crucial to verify the authenticity of download sources and to rely on official vendor websites for software acquisition. The incident underscores the persistent threat of malvertising and the need for robust endpoint security solutions to detect and prevent the execution of malware like SectopRAT. Further analysis of the campaign's infrastructure and distribution methods is ongoing to identify and mitigate the threat.
Original source — read the full reporting at the publisher:
Read on BleepingComputerGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.