Some trusted features in AI platforms have become a new attack surface, according to monitoring by Huntress’s Security Operations Center over the past nine months. Rather than directly attacking AI models or the companies that develop them, attackers exploited shareable content, publicly published mini-applications, and paid search results to reach users of these platforms.
The avenues identified by Huntress include Claude Artifacts content, Claude conversation-sharing links, and indexable ChatGPT and Grok conversations. These campaigns take advantage of content hosted within a known domain and a design familiar to users, making download instructions or code commands appear legitimate. Even when the service provider removes the content within hours or days, the brief window may be sufficient to reach victims.
FakeAgent Campaign Exploits Claude Artifacts
In July, Huntress identified a campaign it named FakeAgent that affected more than 29 organizations. The campaign began by creating a malicious Claude Artifact hosted on the claude.ai domain, a legitimate domain belonging to the Claude platform. According to the report, the attackers designed a fake download page for the Claude Desktop application, taking advantage of the fact that public Artifacts are intended for lightweight demonstrations and do not undergo extensive scanning, apart from a general warning.
Users searching Bing for the Claude Desktop application were directed to the fake page, after which the download link led to an external domain distributing SectopRAT malware. After Huntress reported the Artifact, Anthropic removed it by July 22, but activity associated with the same redirect domain continued through August.
Fake Installation Guide Inside a Share Link
In another incident, a paid advertisement displayed when searching Google for “Claude on Mac” led to a claude.ai/share link pretending to be an installation guide issued by Apple Support. The page’s presence within Anthropic’s domain removed customary warning indicators, such as a mismatch in the website address or a certificate-related warning.
The guide asked the victim to paste a curl command into Terminal, triggering a six-stage sequence that ended with the installation of MacSync data-stealing malware. The targeted data included cookies, credentials, Keychain secrets, Telegram sessions, SSH keys, and cloud keys.
What Changes in Practice?
The cases show that content appearing within a known platform is no longer sufficient proof of its safety. A link may be valid in terms of its domain, while the instructions, download destination, or command to be executed may be malicious. Huntress also identified another pattern involving the poisoning of search results and indexed conversations in ChatGPT and Grok, causing ClickFix-style instructions to appear instead of legitimate solutions to troubleshooting requests, including searches for ways to free up space on macOS.
The most important takeaway for users and support teams is the need to examine the instructions themselves and the source of files and commands, rather than relying solely on trust in the platform’s name or domain. Details of the latter pattern remain limited in the available material, so its full scope or the number of victims cannot be determined based on the source alone.