As artificial intelligence platforms become increasingly integrated into daily professional workflows, a concerning new avenue for cyberattacks has emerged: the AI platforms themselves. Security researchers at Huntress Security Operations Center (SOC) have identified a significant shift in threat actor tactics, revealing that the primary risk to users stems not from direct attacks on AI companies or their core models, but from the malicious exploitation of AI features that individuals already trust and rely upon. Over the past nine months, Huntress has meticulously documented instances where threat actors have weaponized shareable AI content, public mini-applications, and even sponsored search placements to target AI users and successfully deliver malware.
This evolving threat landscape represents a departure from traditional cybersecurity concerns, which often focused on vulnerabilities within the AI infrastructure itself. Instead, attackers are leveraging the inherent trust users place in established brands and familiar interfaces to facilitate their malicious activities. This strategy capitalizes on the perceived legitimacy of content hosted on or promoted by trusted AI providers, making it more challenging for users to discern between genuine and harmful interactions.
The Weaponization of Legitimate AI Features
Huntress has observed a consistent pattern of threat actors abusing several legitimate AI platform features. These functionalities, designed to enhance user experience and productivity, are being subverted to serve malicious purposes. The core of this exploitation lies in the "trust boundary" that these features inhabit. When users encounter content within a platform they recognize, complete with its associated branding and contextual information, malicious instructions or download links can appear deceptively legitimate.
While these malicious campaigns are often short-lived, sometimes running for mere hours or days before being identified and removed by platform providers, this limited window is sufficient to ensnare unsuspecting victims. The speed at which these attacks are deployed and the rapid takedown procedures highlight the agile nature of both attackers and defenders in this emerging domain.
Case Study 1: FakeAgent – Malvertising via Claude Artifacts
A particularly notable campaign, dubbed "FakeAgent," emerged in July and impacted over 29 organizations. This operation began with the creation of a malicious Claude Artifact hosted on the legitimate claude.ai domain. Claude Artifacts are designed for lightweight demonstrations and typically undergo minimal vetting by Anthropic, the AI company behind Claude, beyond a general disclaimer. Threat actors capitalized on this, constructing a highly convincing fake Claude Desktop download page.

Users actively searching on platforms like Bing for the Claude desktop application were likely to stumble upon this deceptive page. Upon clicking what appeared to be a legitimate download link, they were instead redirected to an external domain. This external site then served the SectopRAT malware, a Remote Access Trojan designed to compromise user systems.
Huntress promptly reported the malicious Artifact to Anthropic, leading to its removal by July 22nd. However, the threat did not immediately dissipate. Incidents linked to the same redirect domain associated with the FakeAgent campaign continued to surface into August, demonstrating the persistence of these attack vectors and the potential for lingering threats even after initial remediation.
Figure 1: Claude Desktop/Cowork phishing page hosted as a Claude Artifact. (Image Source: Huntress Labs)
The implications of this attack are significant. It underscores how features intended for sharing and collaboration can be repurposed for malicious ends. The reliance on the trusted claude.ai domain, coupled with a sophisticated social engineering approach, allowed attackers to bypass common security measures and user skepticism. The success of this campaign highlights the need for increased vigilance regarding content hosted on seemingly secure platforms.
Case Study 2: The Deceptive Claude Install Guide on claude.ai/share
In a separate, yet related incident, a user searching Google for "Claude on Mac" encountered a sponsored search result. This link directed them to a claude.ai/share URL that masqueraded as an Apple Support install guide. The critical element here was the page’s location: residing on Anthropic’s own domain, it bypassed the typical red flags associated with phishing attempts, such as lookalike URLs or certificate warnings.
The fake guide presented a seemingly innocuous instruction: to paste a curl command into their Terminal. This seemingly simple action initiated a complex, six-stage attack chain. The execution of this command led to the deployment of the MacSync stealer, a sophisticated malware designed to exfiltrate sensitive information. MacSync’s capabilities include harvesting browser cookies, user credentials, system keychain secrets, Telegram session data, and even SSH and cloud keys, providing attackers with a comprehensive trove of personal and professional data.
Figure 2: The weaponized claude.ai shared conversation, badged as shared by Apple Support, walking the victim through pasting a curl one-liner into Terminal. (Image Source: Huntress Labs)

This incident further illustrates the effectiveness of leveraging trusted domains. By posing as an official Apple Support guide hosted on a legitimate AI platform, the attackers created a scenario where the user’s trust in both the AI provider and the supposed support content was exploited. The use of a curl command, a common tool for developers and technically savvy users, added another layer of legitimacy to the deceptive instructions.
Case Study 3: AI Poisoning on ChatGPT and Grok
A third distinct attack pattern targets the very advice generated by AI platforms. In December, a routine search for "clear disk space on macOS" yielded high-ranking results from ChatGPT and Grok conversations. Instead of providing legitimate troubleshooting steps, these AI-generated responses offered ClickFix-style instructions, which are essentially disguised commands designed to download and execute malware.
Attackers achieved this by meticulously crafting these conversations, then utilizing the "share" functionality to generate public URLs on the platforms’ trusted domains. Through a technique known as SEO poisoning, they manipulated search engine rankings to push these malicious links to the top of search results for common queries.
The consequence of this tactic was that users, trusting the AI-generated advice and the legitimacy of the chatgpt.com and grok.com domains, would execute the suggested Terminal commands. These commands, in turn, delivered the AMOS stealer, another information-stealing malware.
Figure 3: Top search results and highly rated links via Google Search. (Image Source: Huntress Labs)
The implications of AI poisoning are particularly alarming because they directly corrupt the information provided by AI systems. This can lead to a cascading effect of compromised systems and stolen data, all initiated by seemingly helpful advice from a trusted source. The ability of attackers to manipulate AI outputs and subsequently achieve high search engine rankings underscores the vulnerability of information ecosystems influenced by AI.
Broader Implications and the Evolving Threat Landscape

The findings from Huntress paint a stark picture of the evolving threat landscape in the age of AI. The primary takeaway is that the immediate and most pervasive threat is not necessarily the AI models themselves being compromised, but rather the human element – the user’s trust in familiar interfaces and legitimate-looking content – being exploited through these AI platforms.
This trend has several critical implications for cybersecurity:
- Erosion of Trust: As users become more reliant on AI for information and task completion, the weaponization of these platforms can lead to a broader erosion of trust in digital tools and online information.
- Sophisticated Social Engineering: Attackers are moving beyond simple phishing emails to more nuanced and context-aware social engineering tactics that leverage the perceived authority and functionality of AI platforms.
- Rapid Attack Cycles: The short lifespan of many of these campaigns necessitates rapid detection and response capabilities from both platform providers and cybersecurity defenders.
- Need for Enhanced User Education: Users need to be educated not only about traditional cybersecurity threats but also about the specific risks associated with interacting with AI-generated content and features.
Defensive Strategies for an AI-Augmented World
In response to these emerging threats, cybersecurity professionals and organizations must adopt a multi-layered defense strategy. Huntress emphasizes that these attacks do not typically breach the core security of the AI platforms themselves; rather, they exploit the inherent trust users place in familiar brands and legitimate domains.
Key defensive measures that defenders should implement include:
- Treating Clipboard Execution as a Risk: Given the prevalence of attacks that rely on users copying and pasting commands, organizations should treat clipboard-driven execution as a significant security risk. Implementing policies that restrict or scrutinize script execution originating from the clipboard is crucial.
- Enforcing Application Allow-listing: By maintaining a strict list of approved applications, organizations can prevent the execution of unauthorized or malicious software, even if downloaded through seemingly legitimate channels.
- Monitoring for Suspicious Activity: Continuous monitoring for new scheduled tasks, changes to antivirus exclusions, or unusual network activity can provide early indicators of compromise.
- User Training and Awareness: Comprehensive user training is paramount. Employees should be educated to identify "ClickFix-style" lures and other deceptive content that mimics legitimate AI interactions. This training should focus on critical thinking and verification of information sources.
- Prompt Reporting of Suspicious Content: Encouraging users and security teams to report any suspicious AI-hosted content to the respective platform vendors quickly is vital for rapid remediation and preventing wider dissemination.
The brevity of these attack campaigns, often measured in hours or days, underscores the importance of swift reporting and robust, layered security controls. By shrinking the window of opportunity for attackers, organizations can significantly mitigate the impact of these evolving threats.
Huntress also encourages those interested in understanding these evolving tradecrafts to engage with resources like their "Tradecraft Tuesday" series, where experts delve into the intricacies of attacker methodologies. This ongoing dialogue and knowledge sharing are essential for staying ahead of sophisticated cyber threats in the rapidly advancing field of artificial intelligence.
Sponsored and written by Huntress Labs.








