EXECUTIVE SUMMARY
An active malware campaign dubbed FakeAgent targets corporate users searching for desktop AI applications. Attackers employ malicious search advertisements to distribute a remote access trojan known as SectopRAT across various business sectors. This operation specifically aims to steal sensitive information, including browser credentials, credit card details, and personal files, while establishing persistent remote control over infected endpoints.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY
An active malware campaign dubbed FakeAgent targets corporate users searching for desktop AI applications. Attackers employ malicious search advertisements to distribute a remote access trojan known as SectopRAT across various business sectors. This operation specifically aims to steal sensitive information, including browser credentials, credit card details, and personal files, while establishing persistent remote control over infected endpoints.[emaillocker id="1283"]
By exploiting trust in popular software brands, the threat actors seek financial gain and long-term access to corporate networks through data theft. The attack chain initiates when users click sponsored search results that direct traffic to a fraudulent hosting page mimicking a legitimate vendor. Victims download a malicious executable that uses signed binaries and DLL sideloading to bypass security controls.
Once executed, the malware creates scheduled tasks for persistence and deploys additional payloads hidden within system folders. To avoid detection, the code checks for virtual machines before decrypting its final payload using graphics shaders. This process ultimately establishes a command-and-control channel via blockchain transactions, allowing operators to exfiltrate data and update infrastructure.
THREAT PROFILE:
| Tactic | Technique ID | Technique | Sub-technique |
| Initial Access | T1189 | Drive-by Compromise | — |
| Defense Evasion | T1574.002 | Hijack Execution Flow | DLL Side-Loading |
| Persistence | T1053.005 | Scheduled Task/Job | Scheduled Task |
| Defense Evasion | T1562.001 | Impair Defenses | Disable or Modify Tools |
| Defense Evasion | T1497.001 | Virtualization/Sandbox Evasion | System Checks |
| Defense Evasion | T1027 | Obfuscated Files or Information | — |
| Credential Access | T1555.003 | Credentials from Password Stores | Credentials from Web Browsers |
| Command and Control | T1071.001 | Application Layer Protocol | Web Protocols |
REFERENCES:
The reports contain further technical details:
https://cybersecuritynews.com/fakeagent-campaign-malicious-bing-ads/