DUBAI — UAE enterprises using Anthropic’s Claude for coding and productivity workflows are being urged to verify download sources after researchers disclosed a malvertising campaign that used Bing search ads and a spoofed page hosted within the claude.ai domain to distribute SectopRAT malware, a remote access trojan capable of stealing browser credentials, session tokens and corporate data.
According to security researchers at BleepingComputer, TechRadar and CyberSecurityNews, attackers exploited a content injection flaw to plant a fake “Claude for Desktop” download page on Anthropic’s own domain, lending the lure unusual credibility. Users who clicked sponsored Bing search results were redirected to this page and tricked into installing SectopRAT disguised as the legitimate application. Help Net Security reported that at least 29 organisations globally were compromised before the campaign was identified, with the malware designed to exfiltrate stored passwords, cookies and system information from infected endpoints.
Relevance for UAE Businesses
Claude and similar generative AI tools have seen rapid adoption across UAE financial services, consultancies and technology firms in Dubai and Abu Dhabi, often deployed by individual employees without formal IT vetting. This “shadow AI” usage pattern increases exposure to malvertising schemes that exploit trusted brand domains. The UAE’s Telecommunications and Digital Government Regulatory Authority has previously flagged AI-tool impersonation as a rising vector in regional phishing campaigns, and corporate security teams in the Emirates are advising staff to download AI applications exclusively through verified enterprise app stores or direct vendor channels rather than search engine advertisements.
Investor and Governance Implications
For GCC investors backing AI-adoption ventures and cybersecurity startups, the incident underscores growing demand for endpoint detection tools tailored to AI-tool impersonation, an emerging niche within the region’s cybersecurity sector, which the UAE government has targeted for expansion under its national AI strategy. Corporate boards overseeing digital transformation mandates in Dubai and Abu Dhabi are likely to face renewed pressure to formalise AI procurement policies, restrict ad-driven software installs on corporate networks, and mandate multi-factor authentication to limit damage from credential theft. Anthropic has not issued a regional statement, but UAE-based IT advisories recommend immediate credential resets for any organisation that may have installed unauthorised Claude desktop clients in recent weeks.












