Story perspectives
Malvertising on Claude.ai Infects 29 Organizations with Data-Stealing Trojans
7/25/2026
1 of 1
Story summary
- Malvertising on Anthropic’s Claude.ai domain delivered a data-stealing trojan disguised as Claude Desktop, infecting at least 29 organizations on July 21–22, 2026.
- The “FakeAgent” campaign used a public Claude “Artifact” that received over 7,100 views before Huntress reported it, prompting Anthropic to remove the artifact.
- Clicking a sponsored Bing ad installed the SectopRAT trojan, which Huntress tied to a fake Docker Desktop scam and Microsoft’s Operation Endgame.
