LIVE FEED
Fake Claude App via Bing Ads Delivers SectopRAT Malware

Fake Claude App via Bing Ads Delivers SectopRAT Malware

ATLAS OWASP HIGH Significant risk · Prioritise patching ▲ 7.2 BleepingComputer

Attackers exploited Bing's ad platform and Anthropic's legitimate Claude.ai domain to distribute a fake Claude desktop installer laced with SectopRAT, a feature-rich remote access trojan with info-stealing and HVNC capabilities. The campaign, dubbed FakeAgent, compromised at least 29 organisations in a 48-hour window by abusing Claude Artifacts as a trusted hosting vector — a novel AI platform abuse technique. The incident highlights how threat actors are weaponising AI brand trust and legitimate AI infrastructure as malware delivery mechanisms.

Beagle Backdoor Deployed Through Fake Claude Website

Beagle Backdoor Deployed Through Fake Claude Website

ATLAS OWASP HIGH Significant risk · Prioritise patching ▲ 6.5 BleepingComputer

Threat actors created a convincing fake website impersonating Anthropic's Claude AI to trick developers into downloading a trojanized installer that deploys the new 'Beagle' backdoor alongside a PlugX malware chain. The campaign specifically targets Claude-Code developers by advertising a fraudulent 'high-performance relay service,' suggesting deliberate targeting of the AI developer community. The attack leverages DLL sideloading via a legitimate signed G Data executable to evade detection while establishing persistent remote access.

◉ AI THREAT BRIEFING

Stay ahead of the threat.

Twice-weekly digest of critical AI security developments — every story mapped to MITRE ATLAS and OWASP LLM Top 10. Free.

No spam. Unsubscribe anytime.