Fake Claude Download Page Led to SectopRAT

Help Net Security · Medium sophistication
Last updated July 30, 2026

Attackers abused Anthropic’s Claude “Artifacts” publishing feature to host a convincing fake Claude download page on the real claude.ai domain. Victims found it via a sponsored Bing ad, clicked “Download,” and were redirected to attacker-controlled sites that delivered the SectopRAT remote access trojan. Huntress says employees at 29+ organizations were compromised in just two days.

What happened

Employees searching for the Claude desktop app clicked a sponsored Bing ad that pointed to the genuine claude.ai domain. Instead of landing on an official Anthropic page, they arrived at a public Artifact, a feature that lets Claude users publish content to a shareable link without requiring a Claude account. The Artifact was designed to look like a real Claude download page. Clicking the "Download" button redirected victims first to claude.ai.download-app[.]us and then to downloading-api.it[.]com/html/claude/win, where a malware bundle was served. The payload was SectopRAT, a remote access trojan that grabs and exfiltrates credit card data, personal information, files, and passwords. Huntress reported that employees at at least 29 organizations were compromised over two days in July, and that the Artifact had been viewed 7,100 times before it was taken down.

Why it succeeded

The attack relied on a chain of trust signals that all pointed the wrong way. The ad itself pointed to the genuine claude.ai domain, which gave the initial click a strong sense of legitimacy. Because Claude Artifacts can be published publicly and viewed by anyone without an account, attackers were able to host convincing, professional-looking content directly on infrastructure that users already trust. The only visible warning sign was a short line of text stating that the content was user-generated and unverified, a disclaimer that is easy to miss on an otherwise polished page.

What to watch for

  • Sponsored search results being used to advertise software downloads
  • A "Download" button that redirects away from the domain you started on
  • Small disclaimers noting that a page's content is user-generated or unverified
  • Installer bundles arriving from unfamiliar external domains rather than a vendor's own infrastructure

Building resistance

This case shows that a familiar domain in a search ad is not proof of safety. Even legitimate platforms can be used to host attacker-controlled content when they allow public, unauthenticated publishing. Employees, IT staff, developers, and anyone who downloads software as part of their role should be encouraged to avoid sponsored ad results for software downloads and instead navigate directly to vendor sites they type in themselves or have bookmarked. Teams should also build habits around scrutinizing redirects during any download flow: if a download button sends the browser to a different, unfamiliar domain, that is a reason to stop and verify before proceeding. Reinforcing awareness of small trust-and-safety disclaimers, like notices that content is user-generated and unverified, can also help employees recognize when a page that looks official may not be.

Key findings

  • Employees at “at least 29 organizations were compromised over two days in July” after searching for the Claude desktop app and clicking a sponsored Bing ad.
  • The sponsored ad “pointed to the genuine claude.ai domain” but landed users on an attacker-published public Artifact that looked like a real Claude download page.
  • The page included a subtle disclaimer: “Content is user-generated and unverified.”
  • Clicking “Download” redirected to external attacker domains (claude.ai.download-app[.]us then downloading-api.it[.]com/html/claude/win) to deliver a malware bundle.
  • The payload was SectopRAT, described as a RAT that “grabs and exfiltrates user credit card data, personal information, files, and passwords.”
  • Huntress reported the Artifact; it “was taken down” and had “been viewed 7,100 times.”

Who’s being targeted

  • Commonly targeted roles: All employees, IT, Developers, Procurement/Operations (software requesters).
  • Affected industries: Multiple industries (29+ organizations affected; not specified).
  • Attack channels: email.
  • Impersonated: Anthropic / Claude download page.

Red flags to watch for

  • Sponsored ad results used for software downloads
  • Download button redirects off the trusted domain to lookalike/odd domains
  • Subtle disclaimer that content is “user-generated and unverified”
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How did attackers use claude.ai to spread malware?

Attackers published a public Artifact on claude.ai that looked like a legitimate Claude desktop app download page, then promoted it through a sponsored Bing ad. Clicking download redirected victims to attacker-controlled domains that served the SectopRAT malware.

What is SectopRAT?

SectopRAT is a remote access trojan described as grabbing and exfiltrating user credit card data, personal information, files, and passwords.

How many organizations were affected by this attack?

According to Huntress, employees at at least 29 organizations were compromised over two days in July after clicking the sponsored ad.

How can I tell if a software download page is fake?

Watch for sponsored ad results used for software downloads, download buttons that redirect to unfamiliar domains, and small disclaimers noting that content is user-generated and unverified.

Read the video transcript

In July, employees at at least 29 organizations got hacked just by searching for the Claude desktop app and clicking a sponsored Bing ad. The ad pointed to the real claude.ai, but opened an attacker-made Artifact that looked like a legit Claude download page, with a tiny line saying ‘Content is user-generated and unverified.’ Clicking Download silently bounced them off claude.ai to claude.ai.download-app.us and then downloading-api.it.com/html/claude/win, dropping SectopRAT, malware that can grab credit cards, personal files, and passwords. Here’s the move: never install apps from sponsored search results. For Claude or any software, type the vendor’s site yourself or use a saved bookmark, then download only from there.

Similar attacks

Bank Impersonation Phish Pushes Remote Tool

Bank Impersonation Phish Pushes Remote Tool

A real, active phishing campaign impersonating Bank of America tricks victims into downloading a fake “Account Guard” that installs ScreenConnect remote access on Windows, while Mac users are redirected to a credential-stealing page asking for banking and identity details. Separately, Microsoft…

August 6, 2026
Fake Claude App and Alert Apps Drive New Scams

Fake Claude App and Alert Apps Drive New Scams

This roundup describes multiple real-world campaigns where attackers trick people into installing malicious software that looks legitimate (a fake Claude desktop app, a fake emergency alert app, and banking-malware phishing). The common pattern is “looks normal, feels urgent,” leading users to…

July 23, 2026
ClickFix Trick Spreads ACR Stealer via Paste-Run

ClickFix Trick Spreads ACR Stealer via Paste-Run

Microsoft observed real-world campaigns where victims were tricked by “ClickFix” prompts into pasting a command into Windows Run, which then installed ACR (Amatera) Stealer. The malware steals saved browser passwords, live session tokens, and Microsoft 365/OneDrive/SharePoint files, meaning…

July 17, 2026
Vishing Lures, Fake Identities, and Repo-Trap Attacks

Vishing Lures, Fake Identities, and Repo-Trap Attacks

This recap describes multiple real-world social-engineering-driven attacks, including vishing calls that push employees to spoofed login pages and a supply-chain trick where cloning/opening a GitHub repo in developer tools triggers malware. It also highlights an unusual case where an AI model…

August 10, 2026
Hotel Wi‑Fi Lures and Entra Vishing Hit Users

Hotel Wi‑Fi Lures and Entra Vishing Hit Users

The article reports real-world social engineering operations, including a hotel Wi‑Fi campaign that pushed fake updates and device-code phishing to steal Microsoft 365 access. It also describes an alleged Microsoft Entra vishing campaign tied to data theft claims at Brinks Home, reinforcing the…

August 7, 2026
Hotel WiFi Scam Pushes Fake Updates and Malware

Hotel WiFi Scam Pushes Fake Updates and Malware

A Russia-linked threat group compromised hotel WiFi captive portals to redirect guests to fake “verification” pages. Victims were pushed toward either copying commands into a terminal to install malware or entering Microsoft credentials on spoofed login pages that added an attacker-controlled…

August 7, 2026