Attackers are abusing trusted AI platform features like Claude Artifacts, claude.ai/share links, ChatGPT, and Grok conversations to lure victims into downloading malware or running malicious commands. Huntress says campaigns such as FakeAgent, MacSync, and AMOS show how search poisoning and platform trust can be weaponized against users, even on real domains. #Claude #ChatGPT #Grok #FakeAgent #SectopRAT #MacSync #AMOS #Anthropic #Huntress
Keypoints
- Attackers are abusing trusted AI platform features to reach victims.
- Claude Artifacts were used to host a fake Claude Desktop download page.
- The FakeAgent campaign delivered SectopRAT through a malicious redirect.
- claude.ai/share was used to host a fake Apple Support install guide that installed MacSync.
- ChatGPT and Grok shared conversations were poisoned to push AMOS through search results.