Inside FakeAgent: How a Claude Desktop Malvertising Campaign Hit 29 Organizations with SectopRAT

    Date: 08/10/2026

    Severity: High

    Summary

    FakeAgent is a malvertising campaign that targeted at least 29 organizations by using a malicious Claude Artifact hosted on the legitimate Claude.ai domain to distribute a fake Claude Desktop application. The disguised executable ultimately delivered SectopRAT, which can steal passwords, credit card data, personal information, and files, while using VMProtect, VM detection, and Ethereum blockchain-based C2 to evade analysis and maintain communication with attackers. 

    Indicators of Compromise (IOC) List

    Domains/URLs

    claude.ai/public/artifacts/ca456f1f-44c0-42af-b329-4f1c7534a877

    download-app.us

    5ca8758c-02d0-4a72-89c8-d468b66dda41.com

    IP Address

    107.189.24.67

    104.194.133.210

    107.189.26.86

    107.189.21.86

    45.59.124.17

    45.59.125.228

    45.59.122.82

    107.189.17.143

    45.59.122.134

    45.59.122.235

    107.189.22.118

    107.189.20.32

    107.189.20.95

    107.189.24.255

    45.59.117.145

    45.59.114.190

    45.59.123.122

    45.59.117.67

    195.110.58.222

    191.101.80.211

    2.24.131.246

    2.24.131.246

    Hash

    1cd58cfba596da296ab1878d74023e00c399345a1b6c2a0e5446c53563f4e3bb

    26bae4d7012bf59847ab4036a065419c3d4ca47e020479f55b3b2c6d0d21394a

    1fe3646d27d286db8123297e06ae7badf3e26f352a04f91b6d82c28869a91664

    f8acb8f5cf88b77a4c27d7fd6856aa299bb178e85f9963c2fbd447d818da3ed0

    fd826215add30c1319eefa291b6eaf8ddfa7720cfe816c49aef6fe8a88de7939

    BSC Contract

    0xe012d0f34cde9b870e9d9ed566ea5f8fd9b92228

    0xc1907d7be91f95903ad66d775c397302e7dd9228

    Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection

    Detection Query 1 :

    domainname like "5ca8758c-02d0-4a72-89c8-d468b66dda41.com" or url like "5ca8758c-02d0-4a72-89c8-d468b66dda41.com" or siteurl like "5ca8758c-02d0-4a72-89c8-d468b66dda41.com" or domainname like "download-app.us" or url like "download-app.us" or siteurl like "download-app.us" or domainname like "claude.ai/public/artifacts/ca456f1f-44c0-42af-b329-4f1c7534a877" or siteurl like "claude.ai/public/artifacts/ca456f1f-44c0-42af-b329-4f1c7534a877" or url like "claude.ai/public/artifacts/ca456f1f-44c0-42af-b329-4f1c7534a877"

    Detection Query 2 :

    dstipaddress IN ("2.24.131.246","45.59.117.145","45.59.125.228","45.59.122.134","45.59.114.190","107.189.24.255","45.59.122.235","107.189.26.86","104.194.133.210","45.59.117.67","107.189.24.67","45.59.123.122","195.110.58.222","191.101.80.211","45.59.122.82","45.59.124.17","107.189.17.143","107.189.20.95","107.189.22.118","107.189.21.86","107.189.20.32") or srcipaddress IN ("2.24.131.246","45.59.117.145","45.59.125.228","45.59.122.134","45.59.114.190","107.189.24.255","45.59.122.235","107.189.26.86","104.194.133.210","45.59.117.67","107.189.24.67","45.59.123.122","195.110.58.222","191.101.80.211","45.59.122.82","45.59.124.17","107.189.17.143","107.189.20.95","107.189.22.118","107.189.21.86","107.189.20.32")

    Detection Query 3 :

    sha256hash IN ("fd826215add30c1319eefa291b6eaf8ddfa7720cfe816c49aef6fe8a88de7939","f8acb8f5cf88b77a4c27d7fd6856aa299bb178e85f9963c2fbd447d818da3ed0","1cd58cfba596da296ab1878d74023e00c399345a1b6c2a0e5446c53563f4e3bb","26bae4d7012bf59847ab4036a065419c3d4ca47e020479f55b3b2c6d0d21394a","1fe3646d27d286db8123297e06ae7badf3e26f352a04f91b6d82c28869a91664")

    Reference:    

    https://www.huntress.com/blog/fakeagent-claude-desktop-malvertising-ends-in-dotnet-rat                                  


    Tags

    MalwareRATAISectopRATCredential HarvestingFinancial ServicesBlockchain

    « Previous ArticleNext Article »

    Comments

    No records to display

    Looking for Something?
    Threat Research Categories:
    Tags