That 'Claude desktop' download from a search ad may be malware - even when the link really is on claude.ai
If you went looking for the Claude desktop app in the past couple of weeks, the download you grabbed might not have been the real one. Researchers at Huntress uncovered a campaign they've named FakeAgent that used sponsored Bing ads to steer people searching for "Claude desktop" toward a fake download page. The uncomfortable twist: that page was hosted on the genuine claude.ai domain, built as a public "artifact" - a page any user can publish there. It was viewed about 7,100 times over two days in late July before Anthropic took it down.
Click "Download" and you didn't get a chat app. You got SectopRAT, a remote-access trojan that hands an attacker your saved passwords, card details, browser data and files, and lets them quietly operate the machine. Roughly 29 organisations were caught in the window it was live - but the bait, a plain search for a popular app, is exactly what a home user does too.
Two habits shut this down. First, don't install software from search-engine ads, even ones that look official; go to the maker's own site by typing the address yourself. Second, a familiar domain in the link is not proof of safety - big platforms now let users publish their own pages under the main address, and the tiny "content is user-generated and unverified" note is easy to miss. If a download page pushes you to grab an .exe from somewhere unexpected, back out.
The cleaner fix is to stop hunting for installers on the open web at all. Tendvane installs and updates your apps through Windows' own package manager (winget), so the software comes from a vetted source rather than whichever result happened to rank first that day.