rootpwn

Threat Intel

AI Platforms Become New Attack Vectors: Hackers Hijack Claude, ChatGPT and More

As AI tools like Claude, ChatGPT and Grok become integral to daily workflows, threat actors are turning these trusted platforms into launchpads for malware, phishing, and data theft. By weaponizing shareable AI artifacts, exploiting sponsored search results and embedding malicious instructions in seemingly legitimate AI conversations, attackers can deliver ransomware, credential stealers and other payloads with minimal user suspicion. Recent campaigns—FakeAgent’s Claude Artifact redirect to SectopRAT and a fake Apple‑support guide on claude.ai/share that installs the MacSync stealer—show how q

When AI chatbots and search‑enhanced assistants move from novelty to necessity, attackers are finding a new, low‑friction way to reach victims. Rather than attacking the AI companies themselves, threat actors are hijacking the very features users trust to distribute malware, poison search results and convince people to download malicious software.

How the Attack Surface Expands

  • Claude Artifacts – Publicly shareable snippets that appear in a preview pane and can be published via a short link.
  • claude.ai/share URLs – Shareable chat links that can surface in search engines when posted on forums or social media.
  • ChatGPT and Grok conversations – Indexable threads hosted on chatgpt.com and grok.com that rank for troubleshooting queries.

Because these features live on the official domain, carry the platform’s branding and often lack obvious red flags, they create a strong trust boundary that attackers exploit.

Recent Campaigns in Action

FakeAgent – In July, a malicious Claude Artifact hosted on the legitimate claude.ai domain redirected users searching for the “Claude desktop” app to an external site that delivered the SectopRAT ransomware. The artifact was removed by Anthropic on July 22, but the redirect domain kept spamming victims into August.

Fake Apple‑Support Install Guide – A Google search for “Claude on Mac” led users to a sponsored result that opened a claude.ai/share link masquerading as an Apple Support page. The page instructed users to run a curl command that launched the MacSync stealer, a six‑stage chain harvesting cookies, credentials, keychain secrets, Telegram sessions, SSH keys and cloud data.

Both incidents illustrate how a single click on a seemingly legitimate AI‑generated page can trigger a full malware chain. The attacks typically run for only a few hours or days before the platform removes the content, but that window is often enough to compromise dozens of organizations.

Why This Matters for Security Teams

  • AI content is automatically indexed by search engines, amplifying reach.
  • Users trust the platform’s brand, reducing scrutiny of malicious instructions.
  • Removal can be slow; meanwhile, attackers can pivot to new domains.

Security teams should monitor for unusual download links, anomalous search queries, and unexpected redirects from AI platforms. Implementing strict URL filtering and user education on verifying source authenticity can mitigate the risk.

AI Malware Phishing Claude ChatGPT Threat Actors Security

← All news