Malicious Actors Exploit Legitimate AI Features to Distribute Malware

Attackers are abusing trusted AI platforms like Claude, ChatGPT, and Grok by weaponizing shareable content, public mini-apps, and sponsored search results to trick users into installing malware. Huntress researchers observed campaigns such as FakeAgent, which used a malicious Claude Artifact hosted on the real claude.ai domain to hit over 29 organizations. These operations often run for only hours or days before being taken down, but that window is enough to deceive victims.
Huntress monitored these abuses over a nine-month span, noting that malicious content often lives on legitimate domains like claude.ai, which bypasses typical phishing red flags. The FakeAgent operation alone impacted over two dozen organizations before Anthropic removed the artifact, yet related malicious redirects persisted into the following month.
Another scheme used sponsored search results to direct users to a fake Apple support guide hosted on a shared Claude link, ultimately deploying a stealer that exfiltrated browser credentials, keychain data, and cloud keys. Additionally, poisoned ChatGPT and Grok conversations surfaced in search results for common macOS troubleshooting queries, delivering ClickFix-style instructions.
The reliance on trusted AI interfaces means users may lower their guard, making them susceptible to malware delivery through seemingly benign search results or shared links. Individuals seeking technical help and businesses adopting AI tools could face credential theft or ransomware, as these attacks exploit the inherent trust in established platforms. The short lifespan of these campaigns suggests a reactive defense, potentially leaving a window for widespread compromise before providers can respond.