Fake Claude Desktop Installer Delivered SectopRAT RAT via Bing Malvertising
What Happened – A malvertising campaign on Bing promoted a counterfeit “Claude” desktop installer hosted on the legitimate Claude.ai domain. The installer bundled a legitimate JetBrains Chromium component that sideloaded a malicious libcef.dll, which deployed the SectopRAT remote‑access trojan. Between July 21‑22, at least 29 organizations were compromised, with the RAT harvesting passwords, credit‑card data, browser cookies, and VPN credentials.
Why It Matters for Compliance & Audit Readiness
- The incident exemplifies a classic “malicious download” scenario that SOC 2 Access Control (CC6.1) and Security Awareness policies are designed to prevent and evidence.
- Continuous monitoring of user‑download behavior and proof of employee training provide defensible audit evidence that the organization exercised due diligence.
- Verisq’s Security Awareness Training capability helps embed the required training controls and supplies evidence of completion for SOC 2 auditors.
Who Is Affected – Enterprises across technology, professional services, and any sector where end‑users download third‑party software.
Recommended Actions
- Map the incident to SOC 2 CC6.1 (Access Control) and CC6.2 (Security Awareness) controls; collect logs of download events and training records as audit evidence.
- Deploy endpoint protection that blocks unsigned DLL sideloading and enforce application allow‑lists.
- Conduct a targeted phishing‑simulation campaign to reinforce safe‑download practices.
Source: BleepingComputer
Technical Notes
- Attack vector: Malvertising → phishing‑style lure → malicious installer.
- Malware: SectopRAT (aka ArechClient2) with HVNC, credential‑stealing, and EtherHiding C2 retrieval via BNB Smart‑Chain transactions.
- Persistence: Scheduled task installed via a fake
DockerDesktop.exe. - Anti‑analysis: VMProtect packing, GPU/VRAM checks, VM detection.
Source: BleepingComputer