Threat Actors Weaponize Trusted AI Domains to Deliver Malware
Attackers are using Claude, ChatGPT, and Grok to bypass security filters via shared conversations and public artifacts.
Cybersecurity firm Huntress has discovered that threat actors are weaponizing legitimate features of popular AI platforms to deliver malware. By exploiting the inherent trust associated with domains like claude.ai and chatgpt.com, attackers are successfully bypassing traditional security red flags.
These campaigns leverage shareable conversations, public "Artifacts," and SEO poisoning to trick users into executing malicious commands or downloading infected files. In the "FakeAgent" campaign, attackers used a malicious Claude Artifact to host a fraudulent Claude Desktop download page, which redirected victims to the SectopRAT malware. This specific campaign targeted more than 29 organizations in July.
Other attacks specifically targeted macOS users. Threat actors deployed claude.ai/share links disguised as Apple Support guides, prompting users to run curl commands that installed the MacSync stealer. Additionally, attackers used SEO poisoning and malicious advertisements to push shared ChatGPT and Grok conversations to the top of Google search results for macOS troubleshooting. These lures, utilizing "ClickFix" style tactics, were used to deliver the AMOS stealer.
The Erosion of the Trust Boundary
As AI tools become deeply integrated into professional workflows, users have developed a high level of trust in content hosted on official AI domains. This shift represents a strategic pivot by threat actors; rather than attempting to attack the AI models themselves, they are exploiting the "trust boundary" of the platforms' sharing and publishing features. These features often have minimal vetting for public content, allowing malicious instructions to reside on legitimate infrastructure.
According to the Huntress SOC, the primary day-to-day risk now stems from threat actors abusing the AI features people already rely on, rather than direct attacks on the AI companies or their underlying models.
Implications for Cybersecurity
This trend marks a sophisticated evolution in social engineering where a "trusted domain" is no longer a reliable indicator of safety. Because the malicious instructions are hosted on the actual domains of reputable AI providers, they can easily bypass URL filters and user skepticism. This effectively renders traditional security advice—such as "check the URL before clicking"—obsolete for these platforms.
What to Watch
Security professionals should monitor for an increase in "living-off-the-trusted-domain" attacks as AI platforms introduce more collaborative and public-facing features. While the current campaigns focus heavily on macOS stealers and RATs, the ability to host convincing phishing pages and command-line instructions on trusted AI domains provides a scalable blueprint for broader corporate espionage and data theft. It remains to be seen how AI providers will implement stricter vetting for shared content to mitigate these risks.