Hackers hid dangerous malware on a hidden page on Anthopic’s Claude.ai domain



  • Huntress detects a malicious Claude artifact that spoofs Claude Desktop and spreads SectopRAT malware
  • Victims were redirected via Bing ads, infecting at least 29 organizations between July 21 and 22, 2026.
  • Claude removed the artifact after more than 7,000 views; Malvertising risks persist despite artifact disclaimers.

At least 29 organizations have been infected with a Remote Access Trojan (RAT) after mistaking a public Claude artifact for a legitimate Claude page.

A Claude artifact is an interactive document, or a piece of code, that is generated by AI and then hosted on the Claude platform. It can then be shared with others as an example or proof of concept for different solutions. The link to an artifact usually looks like this:

Leave a Comment

Your email address will not be published. Required fields are marked *