What happened
Huntress disclosed (published July 22-23, 2026) a malvertising campaign dubbed 'FakeAgent' in which attackers exploited Claude's Artifacts feature — which lets any user publish interactive content to a public link under the claude.ai domain — to host a convincing fake Claude Desktop download page, bypassing typical domain-reputation heuristics because the hosting domain itself was legitimate.
Why it matters
This is a novel abuse of a GenAI platform's own trusted-content-hosting feature as a malware distribution vector: because the artifact lived on Anthropic's real domain with a valid certificate, it defeated standard anti-phishing controls that rely on domain reputation, showing that any AI platform allowing user-published content on its primary domain becomes an attractive, hard-to-detect distribution surface for attackers.
Attack vector
Attackers published a malicious public Claude Artifact on the legitimate claude.ai domain, imitating Anthropic's Claude Desktop download page. Victims searching for the Claude Desktop app on Bing clicked a sponsored ad pointing to the genuine claude.ai artifact link, which redirected to attacker infrastructure (claude.ai.download-app[.]us, downloading-api.it[.]com) serving a repurposed signed JetBrains binary vulnerable to DLL sideloading that deployed SectopRAT (VMProtect-packed, GPU-based anti-VM checks, DirectX-shader payload decryption, EtherHiding C2 via Ethereum blockchain).
Affected systems
Anthropic Claude Artifacts (public-artifact hosting feature on claude.ai)
Mitigation
Anthropic removed the malicious artifact after Huntress's report; users should never trust top-level domain alone when downloading software via search-ad links, and should verify the 'Content is user-generated and unverified' disclaimer on Claude Artifacts.