Close Menu
  • Tech Insights
  • Laptops
  • Mobiles
  • Gaming
  • Apps
  • Money
  • Latest in Tech
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram
TechzLab – Tech News, Gadgets, Mobile, IT Updates & ReviewsTechzLab – Tech News, Gadgets, Mobile, IT Updates & Reviews
  • Tech Insights
  • Laptops
  • Mobiles
  • Gaming
  • Apps
  • Money
  • Latest in Tech
TechzLab – Tech News, Gadgets, Mobile, IT Updates & ReviewsTechzLab – Tech News, Gadgets, Mobile, IT Updates & Reviews
Home » Hackers hid dangerous malware on a page hidden in Anthopic’s Claude.ai domain
Laptops

Hackers hid dangerous malware on a page hidden in Anthopic’s Claude.ai domain

By July 24, 2026No Comments2 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
Share
Facebook Twitter LinkedIn Pinterest Email

  • Huntress spots malicious Claude Artifact spoofing Claude Desktop, spreading SectopRAT malware
  • Victims were redirected via Bing ads, infecting at least 29 organizations between July 21–22, 2026
  • Claude removed the artifact after 7,000+ views; malvertising risks persist despite disclaimers on artifacts

At least 29 organizations have been infected with a Remote Access Trojan (RAT) after mistaking a public Claude Artifact for a legitimate Claude page.

A Claude Artifact is an interactive document, or piece of code, that the AI generates and then hosts on the Claude platform. It can then be shared with other people as an example, or proof of concept, for different solutions. The link to an artifact usually looks something like this:

claude[.]ai/public/artifacts/ca466f1f-21c0-42af-b329-8f1c7534a891

Latest Videos FromTechRadar

Claude Artifacts are often used for phishing and other forms of scams, and we’ve seen it in ClickFix attacks in the past. Claude responded by adding a disclaimer to every artifact, stating that the content is user-generated and thus unverified.

In this particular case, a malicious artifact was created to spoof the download page for Claude Desktop. Victims would get redirected to an attacker-controlled domain, where instead of the Claude app, they’d download SectopRAT, a remote access trojan capable of stealing credit card data, personal information, files, passwords, and more.

You may like

The artifact was then promoted on Bing, showing up at the very top of search results to people searching for “Claude Desktop App”.

For years, the cybersecurity community has warned about malvertising, urging users to double-check the domain before clicking on any links, even promoted ones. However, the problem here is that the ad takes the victims to the legitimate Claude domain, making scrutiny that much harder.

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

The campaign was spotted by security researchers Huntresswho said that between July 21 and July 22, 2026, their SOC “lit up with a swathe of unusual executable installs, Defender exclusions, and anomalous persistence across 29 organizations, all coming from ClaudeDesktop.exe.”

Claude has since removed the malicious artifact, but not before it raked up more than 7,000 views. It is possible that other organizations, outside Huntress’ field of view, also fell victim to this scam.


Best antivirus software header

The best antivirus for all budgets

Our top picks, based on real-world testing and comparisons

Google logo on a black background next to text reading 'Click to follow TechRadar'

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.


Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

I think the Surface Laptop for Business might be the smartest and most effective work device Microsoft has ever produced — but I’m most enamored with this one key privacy feature

July 28, 2026

The Best Laptops We’ve Tested for Kids in 2026 – PCMag

July 27, 2026

It’s not just OpenAI models escaping and running riot — experts show how Claude Cowork can break its bonds and access Mac files

July 26, 2026
Leave A Reply Cancel Reply

Comment moderation is enabled. Your comment may take some time to appear.

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Latest
  • Samsung Galaxy Z Fold 8 review: a shot in the arm for the foldables market August 3, 2026
  • Best MagSafe wallets of 2026: Expert tested and reviewed August 3, 2026
  • ‘It’s without a doubt one of the least detrimental privacy-focused solutions to your mobile experience’: I spent a month testing GrapheneOS — and it almost made me ditch my Android phone entirely July 30, 2026
  • Low-power AI could define the next era of global innovation July 30, 2026
  • NYT Strands hints and answers for Wednesday, July 29 (game #878) July 29, 2026
We are social
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • YouTube
  • Vimeo

Subscribe to Updates

Get the latest creative news from Techzlab.

Tags
AI Amazon Anthropic Apple artificial intelligence ChatGPT cybersecurity data centers defense tech Donald Trump electric vehicles Elon Musk evergreens EVs Exclusive Fintech gemini Google Grok In Brief India Layoffs Meta Microsoft Mythos nvidia nvidia gtc Nvidia GTC 2026 Openai Perplexity Polymarket Redwood Materials sam altman Sequoia Capital siri social media Softbank SpaceX Spotify Tesla Tim Cook Truecaller Uber Windows X
Archives
Quick Link
  • Apps (403)
  • From the Editor (4)
  • Gaming (382)
  • Laptops (405)
  • Latest in Tech (404)
  • Mobiles (405)
  • Money (228)
  • Tech Insights (406)
Don't miss

Best MagSafe wallets of 2026: Expert tested and reviewed

August 3, 2026

I tested a premium Linux laptop that’s as light as it is powerful – here’s why I love it

July 29, 2026

Is the Electric Trike the Next Big Thing in Shared Micromobility?

July 28, 2026
Follow us
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • YouTube
  • Vimeo
© 2026 Techzlab.com Designed and Developed by WebExpert.
  • Home
  • From the Editor
  • Money
  • Privacy Policy
  • Contact

Type above and press Enter to search. Press Esc to cancel.