
Fake Claude App and Alert Apps Drive New Scams
This roundup describes multiple real-world campaigns where attackers trick people into installing malicious software that looks legitimate (a fake Claude…
Attackers abused Anthropic’s Claude “Artifacts” publishing feature to host a convincing fake Claude download page on the real claude.ai domain. Victims found it via a sponsored Bing ad, clicked “Download,” and were redirected to attacker-controlled sites that delivered the SectopRAT remote access trojan. Huntress says employees at 29+ organizations were compromised in just two days.
Employees searching for the Claude desktop app clicked a sponsored Bing ad that pointed to the genuine claude.ai domain. Instead of landing on an official Anthropic page, they arrived at a public Artifact, a feature that lets Claude users publish content to a shareable link without requiring a Claude account. The Artifact was designed to look like a real Claude download page. Clicking the "Download" button redirected victims first to claude.ai.download-app[.]us and then to downloading-api.it[.]com/html/claude/win, where a malware bundle was served. The payload was SectopRAT, a remote access trojan that grabs and exfiltrates credit card data, personal information, files, and passwords. Huntress reported that employees at at least 29 organizations were compromised over two days in July, and that the Artifact had been viewed 7,100 times before it was taken down.
The attack relied on a chain of trust signals that all pointed the wrong way. The ad itself pointed to the genuine claude.ai domain, which gave the initial click a strong sense of legitimacy. Because Claude Artifacts can be published publicly and viewed by anyone without an account, attackers were able to host convincing, professional-looking content directly on infrastructure that users already trust. The only visible warning sign was a short line of text stating that the content was user-generated and unverified, a disclaimer that is easy to miss on an otherwise polished page.
This case shows that a familiar domain in a search ad is not proof of safety. Even legitimate platforms can be used to host attacker-controlled content when they allow public, unauthenticated publishing. Employees, IT staff, developers, and anyone who downloads software as part of their role should be encouraged to avoid sponsored ad results for software downloads and instead navigate directly to vendor sites they type in themselves or have bookmarked. Teams should also build habits around scrutinizing redirects during any download flow: if a download button sends the browser to a different, unfamiliar domain, that is a reason to stop and verify before proceeding. Reinforcing awareness of small trust-and-safety disclaimers, like notices that content is user-generated and unverified, can also help employees recognize when a page that looks official may not be.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
Attackers published a public Artifact on claude.ai that looked like a legitimate Claude desktop app download page, then promoted it through a sponsored Bing ad. Clicking download redirected victims to attacker-controlled domains that served the SectopRAT malware.
SectopRAT is a remote access trojan described as grabbing and exfiltrating user credit card data, personal information, files, and passwords.
According to Huntress, employees at at least 29 organizations were compromised over two days in July after clicking the sponsored ad.
Watch for sponsored ad results used for software downloads, download buttons that redirect to unfamiliar domains, and small disclaimers noting that content is user-generated and unverified.
In July, employees at at least 29 organizations got hacked just by searching for the Claude desktop app and clicking a sponsored Bing ad. The ad pointed to the real claude.ai, but opened an attacker-made Artifact that looked like a legit Claude download page, with a tiny line saying ‘Content is user-generated and unverified.’ Clicking Download silently bounced them off claude.ai to claude.ai.download-app.us and then downloading-api.it.com/html/claude/win, dropping SectopRAT, malware that can grab credit cards, personal files, and passwords. Here’s the move: never install apps from sponsored search results. For Claude or any software, type the vendor’s site yourself or use a saved bookmark, then download only from there.

This roundup describes multiple real-world campaigns where attackers trick people into installing malicious software that looks legitimate (a fake Claude…

Microsoft observed real-world campaigns where victims were tricked by “ClickFix” prompts into pasting a command into Windows Run, which then installed ACR…

ClickFix is a fast-growing social engineering tactic that gets people to run malware themselves by pasting a command into Windows Run or macOS Terminal.…

This bulletin describes multiple real-world social engineering campaigns where attackers trick people into trusting a familiar screen, like a search result…

Researchers report an active phishing-as-a-service operation, Forg365, that targets Microsoft 365 users with document/payment-themed lures and techniques that…

This article describes real-world “device code phishing” campaigns where victims are tricked into approving an OAuth device login, granting attackers access…