🔐
Security 📅 2026-07-23 · 08:19 PM IST ⏱ 2 min read

Criminals Disguise Malware as Popular AI Tool Through Search Engine Ads

Scammers used search ads to distribute fake versions of Claude AI containing SectopRAT malware, while Origin Energy suffered a separate data breach.

The Threat Emerges

Cybercriminals have launched a dangerous scheme where they created counterfeit versions of Claude, a well-known artificial intelligence assistant, and promoted these fake applications through paid advertisements on major search engines. Inside these fraudulent programs lurked SectopRAT, a type of malicious software designed to spy on victims and steal their information. Think of it like a burglar disguising themselves as a delivery person to gain entry to your home—users believed they were downloading a legitimate tool, but instead compromised their security.

In a separate incident, Origin Energy, an Australian utility company, disclosed that unauthorized individuals breached their systems and made off with customer information. This exposed sensitive personal details that could be used for identity theft and fraud.

Why This Pattern Matters

These incidents reveal a troubling trend in how attackers operate today. Rather than trying to break through security systems directly, criminals increasingly use manipulation and deception. By purchasing advertisements on search engines, the malware distributors appeared legitimate to everyday users searching for AI tools. This approach is far more effective than sending suspicious emails, because people trust the search results they see.

The SectopRAT malware specifically represents what security experts call a "remote access trojan"—essentially a digital key that gives criminals complete control over an infected computer. Once installed, attackers can monitor your activity, steal passwords, access files, and potentially move through a network to compromise other systems.

What This Means For You

How To Protect Yourself

Download only from official sources. When installing software, bypass search results entirely. Type the company name directly into your web browser, or find the download link on their official website. For Claude, that means visiting Anthropic's legitimate website before downloading anything.

Check web addresses carefully. Fake websites often use URLs that look almost identical to the real thing. Always examine the address bar before entering passwords or information.

Keep your computer updated. Security updates patch vulnerabilities that malware exploits. Enable automatic updates on your operating system and software.

Use antivirus protection. Reputable security software can detect and block many malware variants before they cause damage.

Monitor your accounts. If you're affected by the Origin Energy breach, watch your credit reports and bank statements for suspicious activity. Many credit bureaus offer free monitoring services.

The safest approach is to assume that anything promoted through paid ads deserves extra scrutiny, no matter how legitimate it appears.

These incidents demonstrate that security requires constant vigilance in an environment where criminals invest real resources in sophisticated deception campaigns.

📎 This is original ITVedas reporting. This story was inspired by coverage from bleepingcomputer.com. Visit the source for their original reporting.

Want to understand the technology behind this story? ITVedas has beginner-friendly guides on every IT topic.

Explore IT Chapters →