Threat actors are increasingly exploiting trusted artificial intelligence (AI) platforms by weaponizing their legitimate features to deliver malware and steal sensitive data, according to observations from the Huntress Security Operations Center (SOC). Over the past nine months, Huntress has tracked multiple campaigns that leverage shareable AI content, public mini-applications, and sponsored search placements to target users. These attacks do not compromise the AI platforms themselves but rather abuse the trust users place in familiar brands and legitimate domains.
One observed tactic involves the abuse of Claude Artifacts, which are content snippets generated by Anthropic's Claude AI and displayed in a chat preview pane. These artifacts can be published and shared via public links on the claude.ai domain. In July, a campaign dubbed "FakeAgent" affected over 29 organizations. Attackers created a convincing fake Claude Desktop download page hosted as a malicious Claude Artifact. Victims searching Bing for a Claude desktop application were directed to this fake page, where a seemingly legitimate download link redirected them to an external domain that delivered the SectopRAT malware. Huntress reported the artifact, and Anthropic removed it by July 22, though incidents linked to the same redirect domain persisted into August.
Another incident involved a weaponized claude.ai/share link. A victim searching Google for "Claude on Mac" clicked a sponsored search result that led to a shared Claude conversation. This conversation, posing as an Apple Support install guide, instructed the victim to paste a curl command into their Terminal. This action initiated a six-stage attack chain that deployed the MacSync stealer, which harvested cookies, credentials, keychain secrets, Telegram sessions, and SSH and cloud keys. The page's presence on Anthropic's legitimate domain, claude.ai, lent it an air of authenticity, lacking typical red flags like lookalike URLs or certificate warnings.
A third pattern of attack targets AI-generated troubleshooting advice itself. In December, attackers used SEO poisoning to push high-ranking ChatGPT and Grok conversations to the top of Google search results for queries like "clear disk space on macOS." These conversations, hosted on the legitimate chatgpt.com and grok.com domains, provided "ClickFix-style" instructions rather than actual solutions. Victims who trusted the advice and executed the suggested Terminal commands unknowingly deployed the AMOS stealer.
These campaigns often operate for only hours or days before the malicious content is removed by the platform providers, but this short window is sufficient to trick victims. The core issue is not a breach of the AI platform's security but rather the exploitation of user trust in the platform's branding and domain.
To mitigate these risks, security professionals recommend treating clipboard-driven execution and AI-assisted troubleshooting as potential security threats. Organizations should restrict script execution from the clipboard, enforce application allow-listing, and monitor for new scheduled tasks and changes to antivirus exclusions. User training is also crucial to help individuals identify "ClickFix-style" lures. Promptly reporting suspicious AI-hosted content to the respective platform vendors can help shrink the window of opportunity for attackers.






