Attackers abused Anthropic's Claude Artifacts feature to host a malicious redirect on the legitimate claude.ai domain, funneling users who clicked on a sponsored Bing ad for the Claude desktop app to a spoofed download site distributing SectopRAT malware. The article does not describe a software vulnerability with specific affected versions or a patch, but rather a social engineering campaign exploiting a legitimate platform feature. IT professionals should educate users on the risks of clicking sponsored search ads and verify download sources directly from official vendor websites.
A threat actor abused Anthropic’s Claude Artifacts feature to funnel users toward malware, Huntress researchers have disclosed. Employees at at least 29 organizations were compromised over two days in July, after searching for the Claude desktop app and clicking a sponsored Bing ad. The ad pointed to the genuine claude.ai domain, but landed on an attacker-published public artifact, which redirected them to a spoofed download site serving SectopRAT. What are Claude Artifacts? Artifacts are a … More → The post How attackers hosted a fake Claude download page on the claude.ai domain appeared first on Help Net Security .