Full Breakdown
Malvertising Campaign Hijacks Claude.ai Artifact to Deploy SectopRAT Remote Access Trojan (RAT)
7/25/2026, 11:58:47 AM
Core Event: Fraudulent Claude Artifact Leads to Widespread Infection
In a coordinated malvertising operation uncovered by cybersecurity firm Huntress, a public “Artifact” hosted on Anthropic’s Claude.ai domain was crafted to mimic the download page for Claude Desktop. When employees searched for “Claude Desktop App” on Bing on July 21 and July 22 2026, a sponsored link directed them to the malicious artifact, which then redirected to an attacker-controlled site delivering a counterfeit ClaudeDesktop.exe installer. The installer deployed the SectopRAT remote-access trojan, stealing credit-card data, passwords, files and other personal information. Huntress reports that at least 29 organizations were compromised during the two-day window.
Technical Mechanics and Scale
The payload leveraged DLL sideloading, pairing a tampered file with a legitimate, signed JetBrains component so the malicious code executed under the guise of a trusted program. To resist analysis, the malware was wrapped in commercial protection software and incorporated checks for virtual-machine or sandbox environments, aborting execution if detected. Command-and-control traffic was concealed within Ethereum blockchain transactions—a technique dubbed “EtherHiding.” Huntress’ blog notes that the malicious artifact accumulated over 7,000 views before removal; another source cites 7,100 views, indicating a minor reporting discrepancy.
Official Responses
Anthropic responded by adding a disclaimer to every Claude.ai artifact, stating that content is user-generated and unverified. Following Huntress’ notification, the malicious page was taken down from the Claude.ai domain. Huntress also disclosed that its analysts employed Claude itself to assist in reverse-engineering the encryption scheme used by the malware.
Impact and Broader Implications
The incident underscores a growing threat vector: attackers exploiting trusted AI-platform domains to bypass user caution. Because the initial link appeared on Anthropic’s own domain, victims had little reason to suspect foul play before the redirect. Security experts advise organizations to verify software downloads through official channels rather than sponsored search results, especially as AI tools become more ubiquitous.
Conflicting Reports & Gaps
Sources differ on the exact number of artifact views—one cites “7,000+ views,” while another records “7,100 views.” No public information is available regarding the specific identities of the affected organizations or the ultimate financial impact of the data theft.
