Huntress documented malware-delivery campaigns that weaponized public, indexable content on trusted AI platforms—including Claude, ChatGPT, and Grok—without exploiting vulnerabilities in those services. In one campaign, Bing malvertising directed users searching for Claude Desktop to a fraudulent Claude Artifact hosted on the legitimate claude.ai domain, affecting more than 29 organizations and delivering the SectopRAT remote-access trojan.
Other campaigns used a fake Apple Support installation guide on claude.ai/share to deploy the MacSync macOS malware and SEO-poisoned ChatGPT and Grok conversations to distribute the AMOS infostealer. The attacks exploit confidence in recognizable domains, prominent search results, and copied terminal commands; organizations should require official software download channels, treat AI-supplied commands as untrusted, restrict clipboard-triggered script execution, enforce application allowlisting, and monitor for scheduled-task creation and antivirus-exclusion changes.

Get the infrastructure and lures behind it.
7 events from the most recent confirmed update back to the earliest known activity.
Huntress released case research covering a nine-month set of malware-delivery campaigns that abused public and indexable content features on Claude, ChatGPT, and Grok without breaching the platforms' security controls.
Redirect domains associated with the FakeAgent campaign continued to be used into August 2026 after the malicious Claude Artifact was removed.
The fraudulent Claude Artifact was reported to Anthropic and removed after accumulating approximately 7,100 views.
A Bing sponsored advertisement targeting searches for the Claude desktop client redirected victims to a fraudulent Claude Desktop or Claude Cowork Artifact hosted on claude.ai. The FakeAgent campaign affected employees at more than 29 organizations within two days and delivered the SectopRAT remote-access trojan through a DLL side-loading chain.
Attackers used SEO poisoning to promote malicious shared ChatGPT and Grok conversations for macOS troubleshooting searches. The pages presented ClickFix-style Terminal commands that deployed the AMOS stealer.
WHOIS and Validin data linked the registration email used for download-app[.]us to ten domains registered beginning in December 2025.
A claude.ai/share page impersonating Apple Support instructed macOS users to paste a curl command into Terminal, initiating a six-stage infection chain that deployed the MacSync stealer. MacSync targeted browser cookies, credentials, Keychain secrets, Telegram sessions, SSH keys, and cloud-service keys.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.