A malicious advertising campaign on Microsoft's Bing search engine is leveraging trust in a legitimate AI service to distribute the SectopRAT information-stealing malware. Researchers have uncovered a scheme that presents a counterfeit Claude desktop application, with the malicious file hosted on a subdomain of the authentic claude.ai website.

The campaign, detailed in a report from BleepingComputer, uses paid search placements to direct users searching for the popular Claude AI tool towards the fraudulent download. Its effectiveness hinges on multi-layered exploitation of trust indicators: users typically trust paid search results at the top of a page and view files hosted on an official domain as inherently safe.

By registering a subdomain under the legitimate claude.ai umbrella, attackers bypass a common security heuristic—verifying the domain of a download source. This undermines a basic digital literacy lesson. The downloaded file, disguised as a Claude installer, actually deploys SectopRAT, a remote access Trojan known for stealing browser data, login credentials, and cryptocurrency wallet information.

This incident marks a significant evolution in malvertising tactics targeting users of emerging technology tools. As AI assistants like Claude, ChatGPT, and others see rapid adoption, they become high-value bait for cybercriminals weaponizing demand and brand trust.

For individual users and enterprise IT teams, the campaign is a stark reminder that traditional verification cues are growing less reliable. The lesson extends beyond avoiding "shady" websites—it necessitates more cautious behavior with any executable download, even from seemingly known sources. Security awareness training must now address risks of paid search ads and that reputable domains can host malicious files via subdomains.

The tactic represents a concerning convergence of three trusted elements: prominent ad placement, a legitimate brand domain, and the popularity of an AI product. This combination can easily mislead even cautious users. As the landscape of accessible AI tools expands, both developers and the security community must anticipate that trust ecosystems around these tools will be increasingly targeted by sophisticated threat actors.


微軟Bing搜尋引擎上的一項惡意廣告活動,正利用用戶對合法AI服務的信任,分發名為SectopRAT的數據竊取惡意軟件。研究人員揭露了一項陰謀,該陰謀展示了一個偽造的Claude桌面應用程式,而惡意文件就託管在真實claude.ai網站的子網域上。

這項活動在BleepingComputer的一份報告中有詳細說明,它使用付費搜尋廣告位,將搜尋熱門Claude AI工具的用戶引導至欺詐下載頁面。其有效性建立在多層次的信任指標利用上:用戶通常信任頁面頂部的付費搜尋結果,並認為託管在官方網域上的文件本質上是安全的。

通過在合法的claude.ai域名下註冊子網域,攻擊者繞過了常見的安全啟發式檢查——驗證下載來源的網域。這破壞了一項基本的數碼素養知識。下載的文件偽裝成Claude安裝程式,實際上部署的是SectopRAT,這是一個已知的遠程訪問木馬,專門竊取瀏覽器數據、登入憑證和加密貨幣錢包資訊。

這起事件標誌著針對新興科技工具用戶的惡意廣告策略發生了重大演進。隨著Claude、ChatGPT等AI助手的快速普及,它們已成為網絡罪犯利用需求和品牌信任進行武器化的高價值誘餌。

對於個人用戶和企業IT團隊而言,這項活動是一個嚴厲的提醒,表明傳統的驗證線索正變得越來越不可靠。這教訓不僅僅是避開「可疑」網站——它要求對任何可執行文件的下載都需採取更謹慎的行為,即使看似來自已知的來源。安全意識培訓現在必須涵蓋付費搜尋廣告的風險,以及知名網域也可能通過子網域託管惡意文件。

這種策略代表了三個受信任元素的危險融合:顯著的廣告位、合法的品牌網域,以及AI產品的流行度。這種組合很容易誤導即使是謹慎的用戶。隨著可訪問的AI工具格局不斷擴大,開發者和安全社群都必須預期,圍繞這些工具的信任生態系統將越來越受到複雜威脅行為者的針對。

新聞來源 / Original News Source