- Huntress discovers malicious Claude Artifact spoofing Claude Desktop, spreading SectopRAT malware
- Victims were redirected via Bing ads, infecting at least 29 organizations between July 21 and 22, 2026
- Claude removed the artifact after 7,000+ views; risks of malvertising persist despite artifact disclaimers
At least 29 organizations have been infected with a Remote Access Trojan (RAT) after mistaking a public Claude Artifact for a legitimate Claude site.
A Claude Artifact is an interactive document or piece of code that AI generates and then hosts on the Claude platform. It can then be shared with other people as an example or proof of concept for different solutions. The link to an artifact usually looks like this:
claude[.]ai/public/artifacts/ca466f1f-21c0-42af-b329-8f1c7534a891
Latest videos fromTechRadar
Claude Artifacts are often used for phishing and other scams, and we’ve seen it in the past in ClickFix attacks. Claude responded by adding a disclaimer to each artifact stating that the content is user-generated and thus unverified.
In this particular case, a malicious artifact was created to spoof the Claude Desktop download page. Victims would be redirected to an attacker-controlled domain where, instead of the Claude app, they would download SectopRAT, a remote access Trojan capable of stealing credit card data, personal information, files, passwords and more.
The artifact was then promoted on Bing, appearing at the top of the search results for people searching for “Claude Desktop App”.
For years, the cybersecurity community has warned about malvertising, urging users to double-check the domain before clicking on any links, even foreign ones. The problem here, however, is that the ad takes victims to the legitimate Claude domain, which makes checking that much more difficult.
The campaign was discovered by security researchers Huntress, who said that between July 21 and 22, 2026, their SOC “lit up with a series of unusual executable installations, Defender exclusions, and abnormal persistence across 29 organizations, all originating from ClaudeDesktop.exe.”
Claude has since removed the malicious artifact, but not before it had more than 7,000 views. It is possible that other organizations outside of the Huntress’ purview also fell victim to this scam.
The best antivirus for all budgets
Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews and opinions in your feeds.



