HomeIntelligenceBrief
BREACH BRIEF🟠 High Breach

Fake Claude Desktop Installer Delivered SectopRAT RAT via Bing Malvertising

A Bing‑served malvertising campaign pushed a counterfeit Claude desktop installer that sideloaded the SectopRAT remote‑access trojan, compromising at least 29 organizations and exfiltrating credentials. The event underscores the need for SOC 2‑aligned security awareness and access‑control evidence.

LiveThreat™ Intelligence · 📅 July 24, 2026· 📰 bleepingcomputer.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
3 sector(s)
Actions
3 recommended
📰
Source
bleepingcomputer.com

Fake Claude Desktop Installer Delivered SectopRAT RAT via Bing Malvertising

What Happened – A malvertising campaign on Bing promoted a counterfeit “Claude” desktop installer hosted on the legitimate Claude.ai domain. The installer bundled a legitimate JetBrains Chromium component that sideloaded a malicious libcef.dll, which deployed the SectopRAT remote‑access trojan. Between July 21‑22, at least 29 organizations were compromised, with the RAT harvesting passwords, credit‑card data, browser cookies, and VPN credentials.

Why It Matters for Compliance & Audit Readiness

  • The incident exemplifies a classic “malicious download” scenario that SOC 2 Access Control (CC6.1) and Security Awareness policies are designed to prevent and evidence.
  • Continuous monitoring of user‑download behavior and proof of employee training provide defensible audit evidence that the organization exercised due diligence.
  • Verisq’s Security Awareness Training capability helps embed the required training controls and supplies evidence of completion for SOC 2 auditors.

Who Is Affected – Enterprises across technology, professional services, and any sector where end‑users download third‑party software.

Recommended Actions

  • Map the incident to SOC 2 CC6.1 (Access Control) and CC6.2 (Security Awareness) controls; collect logs of download events and training records as audit evidence.
  • Deploy endpoint protection that blocks unsigned DLL sideloading and enforce application allow‑lists.
  • Conduct a targeted phishing‑simulation campaign to reinforce safe‑download practices.

Source: BleepingComputer

Technical Notes

  • Attack vector: Malvertising → phishing‑style lure → malicious installer.
  • Malware: SectopRAT (aka ArechClient2) with HVNC, credential‑stealing, and EtherHiding C2 retrieval via BNB Smart‑Chain transactions.
  • Persistence: Scheduled task installed via a fake DockerDesktop.exe.
  • Anti‑analysis: VMProtect packing, GPU/VRAM checks, VM detection.

Source: BleepingComputer

📰 Original Source
https://www.bleepingcomputer.com/news/security/fake-claude-app-promoted-by-bing-ads-pushes-sectoprat-malware/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Security Awareness

Phishing and social engineering are a people-and-policy problem.

The Verisq AI Trust Operations platform pairs Security Awareness Training with policy adoption tracking, so human-risk controls are documented and audit-ready.

Explore the Verisq AI Trust Operations platform →