Close Menu
Tech Nova Mindset – Empower Innovation and Forward Thinking

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    The Download: AI doomers, whistleblowing agents, and de-aged livers

    September 15, 2026

    Inside the Inference Hardware Revolution Of 2026

    September 15, 2026

    What must happen for AI’s trillion-dollar gamble to pay off

    September 15, 2026
    Facebook X (Twitter) Instagram
    Trending
    • The Download: AI doomers, whistleblowing agents, and de-aged livers
    • Inside the Inference Hardware Revolution Of 2026
    • What must happen for AI’s trillion-dollar gamble to pay off
    • When AI agents cheated at math, other AI agents blew the whistle on them
    • ‘I Like My Big Rat Wife’: Meet the People Using Chatbots to Write Custom Fiction
    • Donated livers can be made biologically younger
    • Responsible AI for Higher Education
    • The Real AI Disruption Isn’t the Technology. It’s the Company.
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    • Home
    • Gadgets
    • Reviews
    • Tech News
    • Future Tech
    • AI & Robotics
    • How-To Guides
    • More
      • Cybersecurity
      • Startups & Innovation
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    Home»Cybersecurity»How attackers hosted a fake Claude download page on the claude.ai domain
    Cybersecurity

    How attackers hosted a fake Claude download page on the claude.ai domain

    kirklandc008@gmail.comBy kirklandc008@gmail.comJuly 23, 2026No Comments3 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Anthropic launches Claude Opus 4.8, prepares Mythos-class models for all customers
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A threat actor abused Anthropic’s Claude Artifacts feature to funnel users toward malware, Huntress researchers have disclosed.

    Employees at at least 29 organizations were compromised over two days in July, after searching for the Claude desktop app and clicking a sponsored Bing ad.

    The ad pointed to the genuine claude.ai domain, but landed on an attacker-published public artifact, which redirected them to a spoofed download site serving SectopRAT.

    What are Claude Artifacts?

    Artifacts are a Claude.ai feature that renders certain content such as code, documents, diagrams, or full web pages in a panel beside the chat rather than as text in the conversation.

    More importantly, users can publish an artifact to a public link, letting anyone view it without a Claude account.

    In this particular case, the artifact to which potential victims were directed rendered a fully functional page that looked like a legitimate Claude download page, and the fact that it was hosted on the Claude.ai domain completed the illusion.

    The only thing revealing its true nature was a short sentence displayed in the upper left corner, saying: “Content is user-generated and unverified.” However, this disclaimer is easily missed.

    The Claude Artifact showing the fake download page (Source: Huntress)

    Huntress reported the artifact to Anthropic and it was taken down before the company published its findings on July 22. By then, the page had been viewed 7,100 times.

    Delivering the malware

    Clicking on the “Download” button redirected victims to an external domain, first claude.ai.download-app[.]us and subsequently downloading-api.it[.]com/html/claude/win, from which they downloaded a bundle.

    It contained a renamed (but legitimate) signed JetBrains binary vulnerable to DLL sideloading, a tampered libcef.dll carrying the actual malware, and an executable (DockerDesktop.exe) that’s dropped to disk and registered as a scheduled task so that it can keep reinfecting the machine.

    The malware is SectopRAT, a remote access trojan (RAT) that grabs and exfiltrates user credit card data, personal information, files, and passwords.

    Tracing the operator

    The attacker had layered several defences on top of the payloads, and Huntress researchers had to go through considerable effort (and use Claude) to analyze them and unearth the command-and-control address.

    In the end, they discovered connections to previous malware delivery campaigns.

    WHOIS records and the Validin intelligence platform tied the download-app[.]us registration to an email address linked to ten domains going back to December 2025. One of them, polse[.]us, was seized by Microsoft as part of Operation Endgame after being identified as hosting the StealC infostealer.

    Huntress also connected the actor to an April 2026 campaign that used Docker Hub to distribute a fake Docker Desktop installer. That campaign employed the same libcef.dll sideloading trick, and also relied on a trusted domain to disarm suspicion. (And this explains the leftover DockerDesktop.exe filename in this month’s bundle.)

    Their advice for users is not to trust search engine ads and top-level domains implicitly when searching for software to download, as threat actors have become experts in pushing malicious ads via popular search engines and finding ways to host malicious content on legitimate platforms and domains.

    Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

    attackers Claude Claude.ai domain Download Fake hosted Page
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    kirklandc008@gmail.com
    • Website

    Related Posts

    The Download: AI doomers, whistleblowing agents, and de-aged livers

    September 15, 2026

    The Download: AI’s real extinction threat and age-reversal tech for eyes

    September 14, 2026

    From Hacks to Bioweapons, Claude Misuse Is Now Everywhere

    September 12, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Nothing CEO says phone prices are going to keep going up

    June 12, 20267 Views

    The best VPN routers of 2026: Expert tested and reviewed

    June 14, 20263 Views

    Google DeepMind Plans to Track AGI Progress With These 10 Traits of General Intelligence

    March 21, 20263 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Recent Posts
    • The Download: AI doomers, whistleblowing agents, and de-aged livers
    • Inside the Inference Hardware Revolution Of 2026
    • What must happen for AI’s trillion-dollar gamble to pay off
    • When AI agents cheated at math, other AI agents blew the whistle on them
    • ‘I Like My Big Rat Wife’: Meet the People Using Chatbots to Write Custom Fiction

    The Download: AI doomers, whistleblowing agents, and de-aged livers

    September 15, 2026

    Inside the Inference Hardware Revolution Of 2026

    September 15, 2026

    What must happen for AI’s trillion-dollar gamble to pay off

    September 15, 2026

    When AI agents cheated at math, other AI agents blew the whistle on them

    September 15, 2026
    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2026 TechNovaMindset. Designed by By Pro.

    Type above and press Enter to search. Press Esc to cancel.