mimile
mimile.ai
Back to feed

Fake Claude download page on claude.ai domain compromised 29 firms

AI digest

This digest was compiled by AI from multiple sources — links to the originals are below.

Fake Claude download page on claude.ai domain compromised 29 firms

A threat actor abused Anthropic's Claude Artifacts feature to host a fake download page on the legitimate claude.ai domain, redirecting users to SectopRAT malware. Employees at at least 29 organizations were compromised over two days in July after clicking a sponsored Bing ad. The artifact was viewed 7,100 times before Anthropic took it down on July 22.

The Attack Vector

Huntress researchers disclosed that the attacker published a public Claude Artifact on claude.ai that rendered a fully functional fake download page. The artifact was accessible without a Claude account, and the only disclaimer — "Content is user-generated and unverified" — was easily missed. Clicking the "Download" button redirected victims to an external domain, first claude.ai.download-app[.]us and then downloading-api.it[.]com/html/claude/win.

Malware Delivery

The downloaded bundle contained a legitimate signed JetBrains binary vulnerable to DLL sideloading, a tampered libcef.dll carrying SectopRAT, and an executable (DockerDesktop.exe) that persisted via a scheduled task. SectopRAT is a remote access trojan that exfiltrates credit card data, passwords, and files. Huntress linked the campaign to an April 2026 operation that used Docker Hub to distribute a fake Docker Desktop installer with the same libcef.dll.

Attribution and Takedown

WHOIS records tied the download-app[.]us registration to an email address linked to ten domains since December 2025. One domain, polse[.]us, was seized by Microsoft in Operation Endgame for hosting the StealC infostealer. Huntress reported the artifact to Anthropic, which removed it before the July 22 disclosure. The page had accumulated 7,100 views by then.

What's Next

Anthropic is expected to review its Artifacts moderation policies to prevent similar abuse. It remains unclear whether law enforcement has identified the operator behind the campaign.

2 sources

Fake Claude download page on claude.ai domain compromised 29 firms