- Huntress detects a malicious Claude artifact that spoofs Claude Desktop and spreads SectopRAT malware
- Victims were redirected via Bing ads, infecting at least 29 organizations between July 21 and 22, 2026.
- Claude removed the artifact after more than 7,000 views; Malvertising risks persist despite artifact disclaimers.
At least 29 organizations have been infected with a Remote Access Trojan (RAT) after mistaking a public Claude artifact for a legitimate Claude page.
A Claude artifact is an interactive document, or a piece of code, that is generated by AI and then hosted on the Claude platform. It can then be shared with others as an example or proof of concept for different solutions. The link to an artifact usually looks like this:
claudius[.]ai/public/artifacts/ca466f1f-21c0-42af-b329-8f1c7534a891
Latest videos ofTechnologyRadar
Claude Artifacts are often used for phishing and other forms of scams, and we have seen this in ClickFix attacks in the past. Claude responded by adding a disclaimer to each artifact, stating that the content is user-generated and therefore unverified.
In this particular case, a malicious artifact was created to spoof the Claude Desktop download page. Victims would be redirected to a domain controlled by the attacker, where instead of the Claude app, they would download SectopRAT, a remote access Trojan capable of stealing credit card data, personal information, files, passwords, and more.
The artifact was then promoted on Bing and appeared at the top of search results for people searching for “Claude Desktop App.”
For years, the cybersecurity community has warned about malvertising, urging users to verify the domain before clicking on any links, even promoted ones. The problem here, however, is that the ad takes victims into Claude’s rightful domain, making scrutiny very difficult.
The campaign was spotted by security researchers Huntress, who said that between July 21 and 22, 2026, its SOC “lit up with a series of unusual executable installations, Defender exclusions, and anomalous persistence across 29 organizations, all originating from ClaudeDesktop.exe.”
Claude has since removed the malicious artifact, but not before it racked up more than 7,000 views. It is possible that other organizations, outside of Huntress’ field of vision, have also fallen victim to this scam.
The best antivirus for all budgets
Follow TechRadar on Google News and add us as a preferred source to receive news, reviews and opinions from our experts in your feeds.




