ZeroHour
BleepingComputerpublished ()ingested Sponsored by Huntress Labs

How Threat Actors Are Turning Trusted AI Platforms Into an Attack Surface

mediumPhishing & fraud exploited in the wildimportance 55
AI summary · glm-5.3

Huntress details campaigns abusing Claude Artifacts, claude.ai/share links, and ChatGPT/Grok conversations to deliver SectopRAT, MacSync, and AMOS stealers.

Huntress SOC documented nine months of campaigns in which attackers weaponized trusted AI platform features—Claude Artifacts, public claude.ai/share links, and indexable ChatGPT/Grok conversations—to deliver malware. The July FakeAgent campaign hit more than 29 organizations via a malicious Claude Artifact posing as a Claude Desktop download page that redirected to SectopRAT. A claude.ai/share link disguised as an Apple Support guide tricked a victim into running a curl command that deployed the MacSync stealer, harvesting cookies, credentials, keychain secrets, Telegram sessions, and SSH/cloud keys, while SEO-poisoned ChatGPT and Grok conversations delivered the AMOS stealer via ClickFix-style instructions.

  • FakeAgent hit 29+ organizations via malicious Claude Artifact delivering SectopRAT
  • claude.ai/share page posing as Apple Support guide deployed MacSync stealer via curl command
  • SEO-poisoned ChatGPT/Grok conversations delivered AMOS stealer through ClickFix-style troubleshooting lures
  • Attacks exploit trust in legitimate AI domains; restrict clipboard script execution and allow-list apps

Indicators of compromiseAll →

TypeIndicatorContext
domainchatgpt.comok conversations: shared, indexable conversations hosted on chatgpt.com and grok.com that can rank for troubleshooting searches. Ea
domainclaude.aistarted with a malicious Claude Artifact hosted on the real claude.ai domain. Since public Artifacts are meant for lightweight de
domaingrok.com: shared, indexable conversations hosted on chatgpt.com and grok.com that can rank for troubleshooting searches. Each of these s
Full article792 words · extracted from bleepingcomputer.com · click to collapse

Hackers monitoring targets

As AI platforms become part of daily workflows, attackers have found a new way in: the platforms themselves. The Huntress Security Operations Center (SOC) says the bigger day-to-day risk comes from threat actors abusing the AI features people already trust and rely on, rather than attacks on the AI companies or models themselves.

Over the past nine months, Huntress has tracked incidents in which attackers weaponized shareable AI content, public mini-apps, and sponsored search placement to target AI users and deliver malware.

Legitimate features, hijacked

Huntress has observed threat actors abuse a handful of real AI platform features, including:

  • Claude Artifacts: content Claude generates and displays in a chat preview pane, which users can publish and share via a public link.

  • claude.ai/share links: shareable URLs created when someone publishes a Claude conversation; these can surface in search engines when posted to crawlable spots like forums or social media.

  • ChatGPT and Grok conversations: shared, indexable conversations hosted on chatgpt.com and grok.com that can rank for troubleshooting searches.

Each of these sits inside a trust boundary. Users recognize the platform, the branding, and the surrounding content, so malicious instructions or downloads look legitimate. These campaigns often only run for hours or days before a provider pulls the content down, but that's enough time to trick victims before getting caught.

If you were hit with ransomware, what would you do?

Your files are encrypted, your operations are down, an attacker has named their price, and they're waiting for you to respond. Do you pay? Do you negotiate? Do you even engage at all?

Choose your next move in a simulated ransomware incident, built from tactics Huntress has seen used against real businesses. You'll see how ransomware operators behave when they think they're in control, and what steps you can take for catching an attack before it becomes a negotiation.

Try the Simulator →

FakeAgent: malvertising through a Claude Artifact

In July, Huntress saw a campaign called FakeAgent hit more than 29 organizations. It started with a malicious Claude Artifact hosted on the real claude.ai domain.

Since public Artifacts are meant for lightweight demos and get minimal vetting from Anthropic beyond a generic disclaimer, attackers built a convincing fake Claude Desktop download page.

Victims searching Bing for the Claude desktop app landed on the fake page and clicked what looked like a legitimate download link. Instead, they were redirected to an external domain that delivered the SectopRAT malware.

Huntress reported the Artifact and Anthropic removed it by July 22, but incidents tied to the same redirect domain continued into August.

Figure 1: Claude Desktop/Cowork phishing page hosted as a Claude Artifact.
Figure 1: Claude Desktop/Cowork phishing page hosted as a Claude Artifact.

A fake install guide hiding in claude.ai/share

In a separate incident, a victim searching Google for "Claude on Mac" clicked a sponsored result that led to a claude.ai/share link posing as an Apple Support install guide. Because the page lived on Anthropic's own domain, it carried none of the usual red flags: no lookalike URL, no certificate warning.

The fake guide instructed the victim to paste a curl command into Terminal, kicking off a six-stage chain that deployed the MacSync stealer. It harvested cookies, credentials, keychain secrets, Telegram sessions, and SSH and cloud keys.

Figure 2: The weaponized claude.ai shared conversation, badged as shared by Apple Support, walking the victim through pasting a curl one-liner into Terminal.
Figure 2: The weaponized claude.ai shared conversation, badged as shared by Apple Support,
walking the victim through pasting a curl one-liner into Terminal.

AI poisoning via ChatGPT and Grok

A third pattern targets AI-generated troubleshooting advice itself. In December, a routine search for "clear disk space on macOS" surfaced high-ranking ChatGPT and Grok conversations that gave ClickFix-style instructions instead of real fixes.

Attackers had crafted the conversations, hit "share" to generate a public URL on the platform's trusted domain, and used SEO poisoning to push the link to the top of Google's results.

Because the links lived on real chatgpt.com and grok.com domains, victims trusted the advice and ran the suggested Terminal commands, which delivered the AMOS stealer. 

Figure 3: Top search results and highly rated links via Google Search
Figure 3: Top search results and highly rated links via Google Search

What defenders should do

None of these attacks broke through the AI platform security. They exploited the trust users place in familiar brands and real domains. 

Defenders should treat clipboard-driven execution and AI-assisted troubleshooting as security risks. Restrict script execution from the clipboard and enforce application allow-listing. Watch for new scheduled tasks and antivirus exclusion changes, and train users to spot ClickFix-style lures. Report suspicious AI-hosted content to the platform vendor quickly.

These campaigns tend to be short-lived, but fast reporting and layered controls can shrink the window attackers get to exploit them.

If you’re interested in this kind of tradecraft and exploring how attackers evolve their tactics, join our experts at Tradecraft Tuesday, where we break it all down every month. 

Sponsored and written by Huntress Labs.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.bleepingcomputer.com/news/security/how-threat-actors-are-turning-trusted-ai-platforms-into-an-attack-surface/