Attackers are abusing trusted AI platforms to host malicious content, manipulate search results and deliver malware, according to Huntress.
Over the past nine months, the Huntress Security Operations Center tracked campaigns using shareable AI content, public mini-apps and sponsored search placements. The campaigns targeted users through Claude Artifacts, claude.ai/share links, and shared ChatGPT and Grok conversations.
In July, Huntress observed the FakeAgent campaign affecting more than 29 organizations. Attackers published a malicious Claude Artifact on the real claude.ai domain and used it to imitate a Claude Desktop download page. Users searching Bing were redirected to an external domain that delivered SectopRAT. Anthropic removed the Artifact by July 22, but related redirects continued into August.
In a separate incident, a sponsored Google result led to a claude.ai/share page posing as an Apple Support installation guide. Another campaign, observed in December, used high-ranking ChatGPT and Grok conversations to spread ClickFix-style instructions for clearing disk space on macOS. Users who followed the Terminal commands received the AMOS stealer.
Huntress said the attacks did not break through AI platform security. Instead, they exploited trust in familiar brands, real domains and AI-generated content.
Comments
0No comments yet. Be the first to comment.