← Back to feed
Threat Actors & CampaignsEmerging1 sourceJul 22, 2026 · 20:00via Huntress Blog

Inside FakeAgent: How a Claude Desktop Malvertising Campaign Hit 29 Organizations with SectopRAT

Brief

On July 21 and July 22, Huntress observed a number of attacks that started with a malicious public Claude Artifact hosted on a legitimate Claude domain, and ended in organizations being infected by the SectopRAT stealer.

Read more on Huntress Blog