Hackers hid dangerous malware on a page hidden in Anthopics’ Claude.ai domain


  • Huntress discovers malicious Claude Artifact spoofing Claude Desktop, spreading SectopRAT malware
  • Victims were redirected via Bing ads, infecting at least 29 organizations between July 21 and 22, 2026
  • Claude removed the artifact after 7,000+ views; risks of malvertising persist despite artifact disclaimers

At least 29 organizations have been infected with a Remote Access Trojan (RAT) after mistaking a public Claude Artifact for a legitimate Claude site.

A Claude Artifact is an interactive document or piece of code that AI generates and then hosts on the Claude platform. It can then be shared with other people as an example or proof of concept for different solutions. The link to an artifact usually looks like this:

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top