Home / Technology / Malware Lurks in Claude Desktop Spoof
Malware Lurks in Claude Desktop Spoof
25 Jul
Summary
- Malicious Claude Artifacts impersonated Claude Desktop, spreading malware.
- Victims clicked Bing ads, leading to SectopRAT malware infections.
- At least 29 organizations were affected between July 21-22, 2026.

Malicious actors have exploited Claude Artifacts to distribute the SectopRAT malware, a dangerous remote access trojan. This campaign, detected by Huntress, specifically targeted users searching for the Claude Desktop App on Bing. These users were directed to a deceptive domain via seemingly legitimate ads, where they were tricked into downloading the malware instead of the expected software.
Between July 21 and July 22, 2026, this attack resulted in infections across at least 29 organizations. The compromised artifact, which mimicked the official Claude Desktop download page, garnered over 7,000 views before Claude removed it. While Claude has since taken action, this incident underscores the ongoing threat of malvertising and the potential for AI-generated content to be weaponized for cybercrime.