A string of AI platform malware attacks is turning the features users rely on every day (shareable conversations, public mini-apps, sponsored search results) into delivery mechanisms for infostealers and remote-access trojans. The Huntress Security Operations Center has tracked incidents over the past nine months in which attackers weaponised Claude Artifacts, shareable chatgpt.com and grok.com URLs, and SEO poisoning to reach victims who had every reason to trust what they were looking at.
None of these campaigns cracked the AI platforms themselves. The whole point is that they did not need to.
How AI Platform Malware Attacks Are Constructed
Three distinct techniques have emerged. The first abuses Claude Artifacts, content that Claude generates and displays in a preview pane, which any user can publish and share via a public link. The second exploits the shareable, indexable URLs that claude.ai, chatgpt.com and grok.com generate when a conversation is made public; those links can surface in search engines when posted to forums or social media. The third is straightforward SEO poisoning: attackers craft a conversation full of plausible-sounding troubleshooting advice, hit share, and push the resulting link to the top of Google’s results through normal ranking manipulation.
What ties all three together is the trust boundary. Victims see a real domain, claude.ai, chatgpt.com, grok.com, and the usual red flags simply are not there. No lookalike URL, no certificate warning, no suspicious branding. These campaigns typically run for hours or days before a provider pulls the content, but that window is enough.
FakeAgent: SectopRAT Delivered via a Real Anthropic Domain
In July, Huntress documented a campaign it named FakeAgent, which hit more than 29 organisations. Attackers built a convincing fake Claude Desktop download page inside a genuine Claude Artifact, hosted on the real claude.ai domain. Victims searching Bing for the Claude desktop app landed on the page and clicked what appeared to be a legitimate download link. Instead, they were redirected to an external domain that delivered the SectopRAT malware.
Huntress reported the Artifact and it was removed by 22 July, but incidents tied to the same redirect domain continued into August. According to IT Security Guru, the fake installer was linked to at least ten other domains dating back to December 2025, and analysis of Ethereum-based command-and-control transactions places the operator’s activity as far back as May 2025. The campaign, in other words, was not improvised: the infrastructure had been running quietly for some time before the Claude Artifact angle was deployed.
A separate incident followed a similar geography. A victim searching Google for “Claude on Mac” clicked a sponsored result that led to a claude.ai/share link dressed up as an Apple Support install guide. The page gave no indication anything was wrong, it lived on Anthropic’s own domain. The fake guide instructed the victim to paste a curl command into Terminal, which triggered a six-stage chain that deployed the MacSync stealer. The stealer harvested cookies, credentials, keychain secrets, Telegram sessions, and SSH and cloud keys.
ChatGPT and Grok Conversations Used for ClickFix-Style Lures
A third pattern targets the troubleshooting searches that bring people to AI platforms in the first place. In December, a routine search for “clear disk space on macOS” surfaced high-ranking ChatGPT and Grok conversations that offered ClickFix-style instructions in place of genuine fixes. Attackers had crafted the conversations, generated public URLs on the platforms’ trusted domains, and used SEO poisoning to push those links to the front of results. Victims who followed the Terminal commands received the AMOS stealer.
This pattern sits inside a broader surge. The Hacker News reported at least 20 distinct malware campaigns targeting AI and vibe coding tools between February and March 2026 alone, suggesting that attackers have settled on AI platforms as a reliable and scalable attack surface rather than an opportunistic one.
What Defenders Can Do Now
Huntress recommends treating clipboard-driven execution and AI-assisted troubleshooting advice as security risks rather than neutral activities. Restricting script execution from the clipboard, enforcing application allow-listing, and watching for new scheduled tasks or antivirus exclusion changes are the practical controls. User training should specifically cover ClickFix-style lures, which depend on the victim manually running a command they were handed.
Reporting suspicious AI-hosted content to the platform vendor quickly also matters. Because these AI platform malware attacks are typically short-lived by design, fast reporting shrinks the window attackers have to operate before the content is pulled. The FakeAgent Artifact came down within days of Huntress’s report, but by then, 29 organisations had already been hit, and the underlying infrastructure had been active for the better part of a year.

