{"id":224430,"date":"2026-07-25T09:00:12","date_gmt":"2026-07-25T06:00:12","guid":{"rendered":"https:\/\/digitrendz.blog\/?p=224430"},"modified":"2026-07-25T09:00:12","modified_gmt":"2026-07-25T06:00:12","slug":"attackers-hosted-fake-claude-download-page-on-claude-ai-domain","status":"publish","type":"post","link":"https:\/\/digitrendz.blog\/z\/tech-news\/224430\/attackers-hosted-fake-claude-download-page-on-claude-ai-domain\/","title":{"rendered":"Attackers Hosted Fake Claude Download Page on claude.ai Domain"},"content":{"rendered":"<details class=\"wp-block-details ticss-586932b6 is-layout-flow wp-block-details-is-layout-flow\" open=\"\"><summary>\u25bc Summary<\/summary><p class=\"ticss-0c48f427 has-small-font-size wp-block-paragraph\">&#8211; A threat actor used a sponsored Bing ad for the Claude desktop app to redirect users to a malicious Claude Artifact, which then led to a fake download site serving the SectopRAT malware.<br>&#8211; Employees at 29 organizations were compromised in July 2025 after clicking the ad, which pointed to claude.ai but landed on an attacker-published artifact.<br>&#8211; The fake download page on Claude.ai appeared legitimate, with only a small &#8220;user-generated and unverified&#8221; disclaimer revealing its true nature; it was viewed 7,100 times before being taken down.<br>&#8211; The malware bundle included a legitimate JetBrains binary for DLL sideloading, a tampered libcef.dll carrying SectopRAT, and a persistent reinfection mechanism via a scheduled task.<br>&#8211; Huntress linked the attacker to previous campaigns using the same DLL sideloading technique, including an April 2026 Docker Hub campaign distributing a fake Docker Desktop installer.<br><\/p><\/details>\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n<p class=\"has-drop-cap wp-block-paragraph\"><mark style=\"color:#f34c3e\" class=\"has-inline-color\">A<\/mark> threat actor exploited <a href=\"https:\/\/digitrendz.blog\/z\/entity\/anthropic\/\" class=\"acp-entity-link\" data-entity-id=\"174\" data-entity-category=\"Organization\" title=\"Learn more about Anthropic\" target=\"_blank\" rel=\"noopener noreferrer\">Anthropic<\/a>\u2019s <strong><a href=\"https:\/\/digitrendz.blog\/z\/entity\/claude-artifacts\/\" class=\"acp-entity-link\" data-entity-id=\"7675\" data-entity-category=\"Technology\" title=\"Learn more about Claude Artifacts\" target=\"_blank\" rel=\"noopener noreferrer\">Claude Artifacts<\/a><\/strong> feature to trick users into downloading malware, according to researchers at <a href=\"https:\/\/digitrendz.blog\/z\/entity\/huntress\/\" class=\"acp-entity-link\" data-entity-id=\"56840\" data-entity-category=\"Organization\" title=\"Learn more about Huntress\" target=\"_blank\" rel=\"noopener noreferrer\">Huntress<\/a>. Over two days in July, employees at <strong>at least 29 organizations<\/strong> were compromised after searching for the Claude desktop app and clicking on a sponsored <a href=\"https:\/\/digitrendz.blog\/z\/entity\/bing\/\" class=\"acp-entity-link\" data-entity-id=\"281\" data-entity-category=\"Technology\" title=\"Learn more about Bing\" target=\"_blank\" rel=\"noopener noreferrer\">Bing<\/a> ad.<\/p>\n\n<p class=\"wp-block-paragraph\">The ad directed users to the legitimate <strong>claude.ai<\/strong> domain, but instead of landing on an official download page, victims were taken to an attacker-created public artifact. That artifact then redirected them to a <a href=\"https:\/\/digitrendz.blog\/z\/topic\/spoofed-download-sites\/\" class=\"acp-topic-link\" data-topic-id=\"257463\" title=\"Explore: spoofed download sites\" target=\"_blank\" rel=\"noopener noreferrer\">spoofed download site<\/a> serving the <strong><a href=\"https:\/\/digitrendz.blog\/z\/entity\/sectoprat\/\" class=\"acp-entity-link\" data-entity-id=\"31365\" data-entity-category=\"Technology\" title=\"Learn more about SectopRAT\" target=\"_blank\" rel=\"noopener noreferrer\">SectopRAT<\/a><\/strong> <a href=\"https:\/\/digitrendz.blog\/z\/newswire\/technology\/145280\/microsoft-teams-phishing-attack-spreads-a0backdoor-malware\/\" class=\"acp-article-link\" data-article-id=\"145280\" title=\"Microsoft Teams Phishing Attack Spreads A0Backdoor Malware\" target=\"_blank\" rel=\"noopener noreferrer\">remote access<\/a> trojan.<\/p>\n\n<p class=\"wp-block-paragraph\">Claude Artifacts allow users to render content like code, documents, diagrams, or full web pages in a panel beside the chat. More critically, users can publish an artifact to a public link, enabling anyone to view it without a Claude account. In this attack, the artifact displayed a fully functional page that mimicked a legitimate Claude download page. Because it was hosted on the <strong>claude.ai domain<\/strong>, the illusion was nearly perfect. The only hint of its true nature was a small disclaimer in the upper left corner reading: \u201cContent is user-generated and unverified.\u201d That warning is easy to overlook.<\/p>\n\n<p class=\"wp-block-paragraph\">Huntress reported the artifact to Anthropic, and it was taken down before the company published its findings on July 22. By that point, the page had been viewed <strong>7,100 times<\/strong>.<\/p>\n\n<p class=\"wp-block-paragraph\">When victims clicked the \u201cDownload\u201d button, they were redirected to an external domain , first <strong>claude.ai.download-app[.]us<\/strong> and then <strong>downloading-api.it[.]com\/html\/claude\/win<\/strong> , where they downloaded a malicious bundle. The bundle contained a renamed but legitimate signed <strong><a href=\"https:\/\/digitrendz.blog\/z\/entity\/jetbrains\/\" class=\"acp-entity-link\" data-entity-id=\"788\" data-entity-category=\"Organization\" title=\"Learn more about JetBrains\" target=\"_blank\" rel=\"noopener noreferrer\">JetBrains<\/a> binary<\/strong> vulnerable to <strong><a href=\"https:\/\/digitrendz.blog\/z\/tech-news\/193962\/ai-chatbot-prompts-lead-users-to-cryptojacking-malware-sites\/\" class=\"acp-article-link\" data-article-id=\"193962\" title=\"AI Chatbot Prompts Lead Users to Cryptojacking Malware Sites\" target=\"_blank\" rel=\"noopener noreferrer\">DLL sideloading<\/a><\/strong>, a tampered <strong>libcef.dll<\/strong> carrying the actual malware, and an executable named <strong><a href=\"https:\/\/digitrendz.blog\/z\/entity\/dockerdesktop-exe\/\" class=\"acp-entity-link\" data-entity-id=\"281543\" data-entity-category=\"product\" title=\"Learn more about DockerDesktop.exe\" target=\"_blank\" rel=\"noopener noreferrer\">DockerDesktop.exe<\/a><\/strong> that was dropped to disk and registered as a scheduled task for persistent reinfection. The malware itself is <strong>SectopRAT<\/strong>, a <a href=\"https:\/\/digitrendz.blog\/z\/newswire\/business\/121253\/linkedin-phishing-attack-uses-pen-testing-tool-to-target-executives\/\" class=\"acp-article-link\" data-article-id=\"121253\" title=\"LinkedIn Phishing Attack Uses Pen Testing Tool to Target Executives\" target=\"_blank\" rel=\"noopener noreferrer\">remote access trojan<\/a> that steals credit card data, personal information, files, and passwords.<\/p>\n\n<p class=\"wp-block-paragraph\">Tracing the attacker required significant effort. Huntress researchers had to peel back multiple layers of defense on the payloads, using <a href=\"https:\/\/digitrendz.blog\/z\/entity\/claude\/\" class=\"acp-entity-link\" data-entity-id=\"404\" data-entity-category=\"Technology\" title=\"Learn more about Claude\" target=\"_blank\" rel=\"noopener noreferrer\">Claude<\/a> itself to analyze them and uncover the <strong>command-and-control address<\/strong>. In the process, they found connections to earlier malware campaigns. WHOIS records and the <strong><a href=\"https:\/\/digitrendz.blog\/z\/entity\/validin\/\" class=\"acp-entity-link\" data-entity-id=\"101607\" data-entity-category=\"Organization\" title=\"Learn more about Validin\" target=\"_blank\" rel=\"noopener noreferrer\">Validin<\/a> intelligence platform<\/strong> tied the <strong>download-app[.]us<\/strong> registration to an email address linked to ten domains dating back to December 2025. One of those domains, <strong>polse[.]us<\/strong>, was seized by <a href=\"https:\/\/digitrendz.blog\/z\/entity\/microsoft\/\" class=\"acp-entity-link\" data-entity-id=\"251\" data-entity-category=\"Organization\" title=\"Learn more about Microsoft\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft<\/a> as part of <strong><a href=\"https:\/\/digitrendz.blog\/z\/entity\/operation-endgame\/\" class=\"acp-entity-link\" data-entity-id=\"157029\" data-entity-category=\"Event\" title=\"Learn more about Operation Endgame\" target=\"_blank\" rel=\"noopener noreferrer\">Operation Endgame<\/a><\/strong> after being identified as hosting the <strong>StealC infostealer<\/strong>.<\/p>\n\n<p class=\"wp-block-paragraph\">Huntress also linked the actor to an April 2026 campaign that used <strong>Docker Hub<\/strong> to distribute a fake Docker Desktop installer. That campaign employed the same <strong>libcef.dll sideloading trick<\/strong> and relied on a trusted domain to disarm suspicion. (This also explains the leftover <strong>DockerDesktop.exe<\/strong> filename in this month\u2019s bundle.)<\/p>\n\n<p class=\"wp-block-paragraph\">Their advice for users is straightforward: Do not implicitly trust search engine ads or top-level domains when searching for software to download. Threat actors have become highly skilled at pushing malicious ads through popular search engines and finding ways to host malicious content on legitimate platforms and domains.<\/p>\n\n<em>(Source: <a href=\"https:\/\/helpnetsecurity.com\/2026\/07\/23\/anthropic-claude-artifacts-download-malware\/\" target=\"_blank\">Help Net Security<\/a>)<\/em>","protected":false},"excerpt":{"rendered":"<p>A threat actor exploited Anthropic&#8217;s Claude Artifacts feature to host a fake download page on the legitimate claude.ai domain, tricking users from a sponsored Bing ad into downloading the SectopRAT remote access trojan, compromising at least 29 organizations over two days in July. The attack used&#8230;<\/p>\n","protected":false},"author":1,"featured_media":224429,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_themeisle_gutenberg_block_has_review":false,"cybocfi_hide_featured_image":"","footnotes":""},"categories":[57,3247,3297,3327,3254],"tags":[238057,238056,238058,103875,238055],"entities":[806,2115,1020,4936,58665,79869,238059,38838,2269,904,119521,22569,76428,66366],"class_list":["post-224430","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-tech-news","category-artificial-intelligence","category-cybersecurity","category-newswire","category-technology","tag-claude-artifacts","tag-claude-download","tag-claude-ai-domain","tag-dll-sideloading","tag-sectoprat","entity-anthropic","entity-bing","entity-claude","entity-claude-artifacts","entity-docker-desktop","entity-docker-hub","entity-dockerdesktop-exe","entity-huntress","entity-jetbrains","entity-microsoft","entity-operation-endgame","entity-sectoprat","entity-stealc","entity-validin"],"_links":{"self":[{"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/posts\/224430","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/comments?post=224430"}],"version-history":[{"count":0,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/posts\/224430\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/media\/224429"}],"wp:attachment":[{"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/media?parent=224430"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/categories?post=224430"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/tags?post=224430"},{"taxonomy":"entity","embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/entities?post=224430"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}