Fake Claude Download Page Led to SectopRAT

Help Net Security · Medium sophistication
Last updated July 30, 2026

Attackers abused Anthropic’s Claude “Artifacts” publishing feature to host a convincing fake Claude download page on the real claude.ai domain. Victims found it via a sponsored Bing ad, clicked “Download,” and were redirected to attacker-controlled sites that delivered the SectopRAT remote access trojan. Huntress says employees at 29+ organizations were compromised in just two days.

What happened

Employees searching for the Claude desktop app clicked a sponsored Bing ad that pointed to the genuine claude.ai domain. Instead of landing on an official Anthropic page, they arrived at a public Artifact, a feature that lets Claude users publish content to a shareable link without requiring a Claude account. The Artifact was designed to look like a real Claude download page. Clicking the "Download" button redirected victims first to claude.ai.download-app[.]us and then to downloading-api.it[.]com/html/claude/win, where a malware bundle was served. The payload was SectopRAT, a remote access trojan that grabs and exfiltrates credit card data, personal information, files, and passwords. Huntress reported that employees at at least 29 organizations were compromised over two days in July, and that the Artifact had been viewed 7,100 times before it was taken down.

Why it succeeded

The attack relied on a chain of trust signals that all pointed the wrong way. The ad itself pointed to the genuine claude.ai domain, which gave the initial click a strong sense of legitimacy. Because Claude Artifacts can be published publicly and viewed by anyone without an account, attackers were able to host convincing, professional-looking content directly on infrastructure that users already trust. The only visible warning sign was a short line of text stating that the content was user-generated and unverified, a disclaimer that is easy to miss on an otherwise polished page.

What to watch for

  • Sponsored search results being used to advertise software downloads
  • A "Download" button that redirects away from the domain you started on
  • Small disclaimers noting that a page's content is user-generated or unverified
  • Installer bundles arriving from unfamiliar external domains rather than a vendor's own infrastructure

Building resistance

This case shows that a familiar domain in a search ad is not proof of safety. Even legitimate platforms can be used to host attacker-controlled content when they allow public, unauthenticated publishing. Employees, IT staff, developers, and anyone who downloads software as part of their role should be encouraged to avoid sponsored ad results for software downloads and instead navigate directly to vendor sites they type in themselves or have bookmarked. Teams should also build habits around scrutinizing redirects during any download flow: if a download button sends the browser to a different, unfamiliar domain, that is a reason to stop and verify before proceeding. Reinforcing awareness of small trust-and-safety disclaimers, like notices that content is user-generated and unverified, can also help employees recognize when a page that looks official may not be.

Key findings

  • Employees at “at least 29 organizations were compromised over two days in July” after searching for the Claude desktop app and clicking a sponsored Bing ad.
  • The sponsored ad “pointed to the genuine claude.ai domain” but landed users on an attacker-published public Artifact that looked like a real Claude download page.
  • The page included a subtle disclaimer: “Content is user-generated and unverified.”
  • Clicking “Download” redirected to external attacker domains (claude.ai.download-app[.]us then downloading-api.it[.]com/html/claude/win) to deliver a malware bundle.
  • The payload was SectopRAT, described as a RAT that “grabs and exfiltrates user credit card data, personal information, files, and passwords.”
  • Huntress reported the Artifact; it “was taken down” and had “been viewed 7,100 times.”

Who’s being targeted

  • Commonly targeted roles: All employees, IT, Developers, Procurement/Operations (software requesters).
  • Affected industries: Multiple industries (29+ organizations affected; not specified).
  • Attack channels: email.
  • Impersonated: Anthropic / Claude download page.

Red flags to watch for

  • Sponsored ad results used for software downloads
  • Download button redirects off the trusted domain to lookalike/odd domains
  • Subtle disclaimer that content is “user-generated and unverified”
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How did attackers use claude.ai to spread malware?

Attackers published a public Artifact on claude.ai that looked like a legitimate Claude desktop app download page, then promoted it through a sponsored Bing ad. Clicking download redirected victims to attacker-controlled domains that served the SectopRAT malware.

What is SectopRAT?

SectopRAT is a remote access trojan described as grabbing and exfiltrating user credit card data, personal information, files, and passwords.

How many organizations were affected by this attack?

According to Huntress, employees at at least 29 organizations were compromised over two days in July after clicking the sponsored ad.

How can I tell if a software download page is fake?

Watch for sponsored ad results used for software downloads, download buttons that redirect to unfamiliar domains, and small disclaimers noting that content is user-generated and unverified.

Read the video transcript

In July, employees at at least 29 organizations got hacked just by searching for the Claude desktop app and clicking a sponsored Bing ad. The ad pointed to the real claude.ai, but opened an attacker-made Artifact that looked like a legit Claude download page, with a tiny line saying ‘Content is user-generated and unverified.’ Clicking Download silently bounced them off claude.ai to claude.ai.download-app.us and then downloading-api.it.com/html/claude/win, dropping SectopRAT, malware that can grab credit cards, personal files, and passwords. Here’s the move: never install apps from sponsored search results. For Claude or any software, type the vendor’s site yourself or use a saved bookmark, then download only from there.

Similar attacks

Device Code Phishing: MFA Bypass at Scale

Device Code Phishing: MFA Bypass at Scale

This article describes real-world “device code phishing” campaigns where victims are tricked into approving an OAuth device login, granting attackers access…

July 31, 2026