logo

How attackers hosted a fake Claude download page on the claude.ai domain

ID: 46367bbd-8167-537c-9d24-31962f96a131

STIX ID: report--46367bbd-8167-537c-9d24-31962f96a131

Feed Name: Help Net Security

Threat Score
75/100

Date Published: 2026-07-23

Date Updated: 2026-07-24

Author: Zeljka Zorz

...
...

Huntress disclosed that attackers abused Anthropic’s Claude Artifacts to publish a fake Claude desktop download page hosted on the claude.ai domain, which redirected victims who clicked a sponsored Bing ad to external sites that delivered a bundle installing SectopRAT via DLL sideloading (tampered libcef.dll alongside a signed JetBrains binary), with a DockerDesktop.exe scheduled task for persistence; the RAT exfiltrates credit-card data, personal information, files, and passwords, and attribution links tie the operator to prior campaigns and domains including one seized during Operation Endgame.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.