Threat Actors Are Abusing Trusted AI Platforms to Deliver Malware

Huntress SOC tracked attackers weaponizing Claude Artifacts, claude.ai share links, and shared ChatGPT and Grok chats to push malware.

Defenders now have a clearer picture of how attackers are turning familiar AI platforms into a delivery channel for malware. Over the past nine months, the Huntress Security Operations Center observed threat actors abusing shareable AI content, public mini-apps, and sponsored search placement to target everyday AI users and install malicious payloads, often by hiding instructions inside the real domains users already trust.

What changed in the attack surface

The risk is not a vulnerability in the AI companies themselves. The bigger day-to-day exposure comes from features that let users publish AI-generated content to a public link on a trusted domain. When those links are posted to crawlable spots like forums or social media, they can rank in search engines and carry the full weight of the platform’s branding. A user who sees claude.ai, chatgpt.com, or grok.com in the address bar has little reason to question what is on the page.

Three platform features showed up repeatedly in the tracked incidents:

  • Claude Artifacts: content generated by Claude and displayed in a chat preview pane that users can publish and share through a public link on claude.ai.
  • claude.ai/share links: shareable URLs created when a Claude conversation is published. Search engines can index them when they appear on crawlable pages.
  • ChatGPT and Grok conversations: shared, indexable conversations hosted on chatgpt.com and grok.com that surface for troubleshooting searches.

Each of these sits inside a trust boundary. Users recognize the platform, the look of the page, and the surrounding content, so malicious instructions and downloads read as legitimate. Campaigns often run for only hours or days before the provider takes the content down, but that window is long enough to catch victims who arrive through search.

FakeAgent: malvertising through a Claude Artifact

In July, a campaign tracked as FakeAgent hit more than 29 organizations. It started with a malicious Claude Artifact hosted on the real claude.ai domain. Because public Artifacts are intended for lightweight demos and carry minimal vetting beyond a generic disclaimer, attackers built a convincing fake Claude Desktop download page inside one. People searching Bing for the Claude desktop app landed on the fake page and clicked what looked like a legitimate download link. That click redirected them to an external domain that delivered the SectopRAT malware. The Artifact was reported and removed by July 22, but incidents tied to the same redirect domain continued into August.

A fake install guide hiding in claude.ai/share

In a separate incident, a user searching Google for "Claude on Mac" clicked a sponsored result that led to a claude.ai/share link posing as an Apple Support install guide. The page sat on Anthropic’s own domain, so it carried none of the usual red flags: no lookalike URL, no certificate warning. The fake guide instructed the user to paste a curl command into Terminal, kicking off a six-stage chain that deployed the MacSync stealer. That payload harvested cookies, credentials, keychain secrets, Telegram sessions, and SSH and cloud keys.

AI poisoning via shared ChatGPT and Grok chats

A third pattern targets AI-generated troubleshooting advice itself. In December, a routine search for "clear disk space on macOS" surfaced high-ranking ChatGPT and Grok conversations that gave ClickFix-style instructions instead of real fixes. Attackers had crafted the conversations, hit share to generate a public URL on each platform’s trusted domain, and used SEO poisoning to push the link to the top of Google’s results. Because the links lived on real chatgpt.com and grok.com domains, victims trusted the advice and ran the suggested Terminal commands, which delivered the AMOS stealer.

What defenders should do

None of these attacks broke through the AI platform security. They exploited the trust users place in familiar brands and real domains. Defenders should treat clipboard-driven execution and AI-assisted troubleshooting as security risks.

  • Restrict script execution from the clipboard and enforce application allow-listing.
  • Watch for new scheduled tasks and antivirus exclusion changes.
  • Train users to recognize ClickFix-style lures, especially when the instruction arrives through a shared AI link.
  • Report suspicious AI-hosted content to the platform vendor quickly.

These campaigns tend to be short-lived, but fast reporting and layered controls can shrink the window attackers get to exploit them.

FAQ

What is a Claude Artifact and why is it risky?

A Claude Artifact is content Claude generates and displays in a chat preview pane, and users can publish it through a public link on claude.ai. Because the Artifact lives on a trusted domain and carries minimal vetting, attackers have used it to host convincing fake download pages that redirect visitors to malware such as SectopRAT.

How do shared ChatGPT and Grok conversations spread malware?

Attackers craft a conversation that looks like real troubleshooting help, click share to generate a public URL on chatgpt.com or grok.com, and use SEO poisoning to rank the link high in Google results. Victims trust the domain and follow the instructions, which have included pasting Terminal commands that install stealers like AMOS.

What can defenders do about AI-hosted lures?

Treat shared AI content as a delivery channel you monitor. Restrict script execution from the clipboard, enforce application allow-listing, watch for new scheduled tasks and antivirus exclusion changes, train users to spot ClickFix-style instructions, and report suspicious AI-hosted pages to the platform so they can be pulled quickly.

SEOScanPro

SEOScanPro, which includes the rank tracker

SEOScanPro has the rank tracker runs a full technical audit of a site and shows the measured result behind every check. Open the rank tracker.


This article summarizes reporting from bleepingcomputer.com. See our editorial disclaimer for how our articles are produced.

🤖
Is your business visible to AI assistants?

Run a free scan to see your AI Visibility Score, SEO rating, and local citation accuracy.

Check Your Score →