Malware Campaign Targets Claude Users
A malicious Claude Artifact led users to download a remote access trojan, compromising at least 29 organizations in a recent campaign.
Security researchers have identified a sophisticated malvertising campaign that leverages the Claude.ai domain to distribute malicious software. By creating a deceptive Claude Artifact, attackers successfully impersonated the official Claude Desktop download page to deliver a potent threat directly to unsuspecting targets.
Exploiting Legitimate Infrastructure
Claude Artifacts function as interactive documents or code snippets hosted directly on the platform. While intended for collaboration and proofs of concept, this feature was weaponized to host a spoofed page that mimicked a software distribution portal. The campaign utilized search engine advertising to place the malicious link at the top of Bing search results for users specifically looking for the Claude Desktop App.
Because the initial point of interaction occurred within a legitimate domain, traditional security warnings regarding domain verification proved insufficient. Once users clicked the link, they were redirected to an attacker-controlled site. Instead of the intended software, victims were prompted to install SectopRAT, a remote access trojan designed to exfiltrate sensitive data, including login credentials, credit card details, and internal files.
Incident Scope and Detection
The campaign, which occurred between July 21 and July 22, 2026, was identified by security researchers at Huntress. The firm reported that their Security Operations Center detected a high volume of suspicious activity stemming from a file named ClaudeDesktop.exe, which triggered numerous alerts regarding anomalous persistence and unauthorized Defender exclusions.
- At least 29 organizations were infected by the malware.
- The malicious artifact accumulated more than 7,000 views before removal.
- The activity was confined to the window of July 21–22, 2026.
The Persistence of Malvertising
Despite Claude implementing disclaimers on artifacts to warn users that content is user-generated and unverified, the campaign demonstrated that visual indicators are often ignored by users operating under the assumption of platform trust. Even after the immediate threat was removed by the platform, the incident underscores the difficulty in mitigating risks when adversaries exploit the trust associated with well-known AI service domains.
Implications for Digital Trust
This incident illustrates a growing challenge for organizations attempting to vet the software their employees interact with daily. When malicious actors successfully hide threats within the infrastructure of a trusted productivity tool, standard security perimeters may fail to detect the initial delivery vector. For businesses, this suggests that monitoring for unusual endpoint behavior, such as unauthorized process execution or modifications to security software exclusions, remains a critical layer of defense, as even legitimate-looking domains can be repurposed as conduits for malware distribution.
Sources
- TechRadar Original source
- remote access trojan Also reporting
Continue Reading
SharedRoot Sandbox Escape in Claude Cowork
A critical vulnerability in Anthropic's Claude Cowork allows AI agents to escape their Linux virtual environment and access host macOS data.
Critical Better Auth SCIM Flaw Enables Takeover
A critical vulnerability in the @better-auth/scim plugin allows authenticated users to hijack accounts via provider ID collisions and bypass security controls.
Image Parsers as Attack Vectors
A critical vulnerability in Bing's image processing reveals the risks of treating image conversion tools as simple infrastructure.