As cited
Copy frozen at (site build).
threat intel
How attackers hosted a fake Claude download page on the claude.ai domain
Threat actors abused Anthropic's Claude Artifacts feature to host a malicious download page on the legitimate claude.ai domain. Employees at 29 organizations were deceived by a sponsored Bing ad linking to this artifact in July, which then redirected them to a spoofed Claude site distributing SectopRAT malware. The attack exploited legitimate platform features to establish trust and bypass initial security skepticism.
Why it matters: Security teams and employees need awareness that trusted vendor domains and sponsored search results can be compromised to deliver malware, making both perimeter controls and user training critical defenses.
- Source published
- First seen by Cybersecurity Tracker