Uncategorized

Hackers Use Fake Claude Desktop App to Disable Defender and Install Remote Access Malware

Cybercriminals are using a counterfeit Claude desktop application to compromise Windows systems, disable key security checks, and install remote-access malware.

The campaign turns a familiar AI software search into a route for credential theft and long-term access. It also shows how trusted-looking download pages can make a dangerous file appear routine.

For organizations, the campaign creates risk beyond one endpoint because stolen credentials may open the door to email, cloud services, and internal systems.

The attack begins with malicious search advertisements that steer victims toward convincing public artifact pages. After a user downloads and runs the supposed installer, the infection moves quickly through several stages.

The final payload is SectopRAT, a remote-access tool that can steal information and give attackers hidden control of an infected device. Such access can let criminals collect files, watch activity, or return later with further instructions.

CyberProof said in a report shared with Cyber Security News (CSN). Its analysts noted that the activity matches the FakeAgent campaign previously tracked in the wild, where attackers abuse public hosting and spoofed installers to deliver malware.

The incident was identified from an alert involving a scheduled task designed to look like a normal software update. Analysts then correlated evidence across the affected endpoint instead of treating that signal as a standalone event.

The case underlines a wider problem for businesses and home users alike. A familiar name is often enough to lower a victim’s guard, particularly when an advertisement appears above legitimate search results.

Recent reporting on fake Gemini installer attacks shows that criminals are also exploiting other popular AI brands to push credential-stealing malware.

Hackers Use Fake Claude Desktop App

Once the victim launched the counterfeit application, it used PowerShell to add exclusions for folders in the user profile, reducing Microsoft Defender visibility over the area where malicious files were staged.

The initial loader then used DLL sideloading, a method that makes a legitimate program load a harmful supporting file. This allowed the code to run in the context of a signed Java Chromium Embedded Framework helper.

The Initial Alert (Source – CyberProof)

The mismatch between the displayed application name and the program’s internal details was a valuable warning sign.

The malware also created a logon-triggered task with elevated privileges while disguising it as a browser updater. That task called a second loader from a user-writable roaming folder, allowing the infection to return after a reboot.

Abuse of native scheduling features remains a proven way to retain access, as shown in reports on Windows scheduled task abuse.

CyberProof’s investigation found that the operators avoided a conventional command server. Instead, the malware relied on EtherHiding, retrieving encrypted connection details from Ethereum blockchain data.

That approach can make takedowns harder because the attacker can rotate infrastructure without relying on one fixed domain or server.

Containment Needs Full Response

Researchers stressed that removing a visible task or one malicious file is not enough when remote-access malware has executed.

In the observed incident, responders isolated the device, removed unauthorized Defender exclusions, revoked user sessions, reset credentials, and reimaged the endpoint. They also reviewed identity and access activity to check whether stolen credentials had been used elsewhere.

Defenders should investigate newly created high-privilege tasks that launch software from Downloads, AppData, or other user-controlled locations.

The agent’s attack chain reconstruction (Source – CyberProof)

They should also flag new antivirus exclusions made soon after a download and inspect unexpected library loads outside normal program folders. Similar chains that combine spoofed software and library loading have appeared in AsyncRAT fake installer campaigns.

Organizations can reduce exposure by directing staff to approved software channels and restricting local installation rights where practical. Search advertisements for developer and AI tools deserve extra caution, even when the landing page looks legitimate.

Monitoring browser-originated downloads, scheduler changes, security-setting changes, and blockchain RPC traffic together can help teams recognize the full attack rather than treating each alert as an isolated event.

That broader view is important when attackers intentionally spread their activity across several ordinary Windows features.

Indicators of Compromise (IoCs):-

TypeIndicatorDescription
File nameClaudeDesktop.exeInitial trojanized loader
File metadataJCEF Helper / jcef_helper.exeInternal metadata associated with the fake loader
File nameDockerDesktop.exeStaged loader used for reboot persistence
File namelibcef.dllVMProtect-packed DLL used in the sideloading chain
File nametempdir.dllDLL name included in the hunting logic for suspicious sideloading activity
File nameClaude.exeSuspicious installer-related file name included in hunting logic
File nameClaudeSetup.exeSuspicious installer-related file name included in hunting logic
File nameDocker Desktop.exeSuspicious installer-related file name included in hunting logic
File pathAppData\Roaming\EdgeUpdate-1b4adb1f\User-writable staging directory
Scheduled taskMicrosoftEdgeUpdateDisguised logon persistence task configured with elevated privileges
Domaindownloading-api.it.comMalvertising download infrastructure
Domainneeitoerw[.]mySuspicious domain observed in the process lineage
IP address153.75.84.173Network infrastructure observed in the process lineage
URL patternclaude[.]ai/public/artifacts/[id]Masqueraded lure artifact page
URL / domaindownload-app.usSuspicious origin included in hunting logic
URL / domainclaude-desktop.gitlab.ioSuspicious origin included in hunting logic
URL / domainclaude.ai.download-app.usSuspicious origin included in hunting logic
URL pathit.com/html/claude/winSuspicious origin included in hunting logic
Domainclaude-code-cmd.squarespace.comSuspicious origin included in hunting logic
URL pathcode.claude.ai/downloadSuspicious origin included in hunting logic
Domaininstall-files.comSuspicious origin included in hunting logic
Keywordclaude-codeSuspicious origin keyword included in hunting logic
Keywordclaude-desktopSuspicious origin keyword included in hunting logic
SHA-256f8acb8f5...Partial hash of the initial payload, as published in the source report

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

2 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

3 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

4 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

4 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

4 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

6 hours ago