2026-07-22 (Back to Inventory) Inside FakeAgent: How a Claude Desktop Malvertising Campaign Hit 29 Organizations with SectopRAT Author(s): Michael Tigges Organization: Huntress Labs win.sectop_rat Open article directly Open article on Archive.org Related Articles 2026-03-04 ⋅ Huntress Labs ⋅ Jai Minton , Ryan Dowd "Malware, from the Outside!": How a Threat Actor Used Fake OpenClaw Installers to Infect Systems with GhostSocks and Information Stealers GhostSocks Vidar 2026-02-16 ⋅ Huntress Labs ⋅ Anna Pham , Michael Tigges ClickFix Won't Die. Neither Will Matanbuchus. A New RAT and a Hands-on-Keyboard Intrusion AstarionRAT Matanbuchus 2026-01-16 ⋅ Huntress Labs ⋅ Anna Pham , Dani Lopez , Tanner Filip Dissecting CrashFix: KongTuke's New Toy KongTuke ModeloRAT
The threat is a malvertising campaign distributing fake Claude Desktop installers that deliver the SectopRAT malware to compromised systems. The article does not provide a CVSS score, specific affected software versions, a fixed version, or a workaround.