"Your files are encrypted, your operations are down, an attacker has named their price, and they're waiting for you to respond," the Huntress Security Operations Center warned — a line that doubles as a simulated ransomware scenario and a warning about how attackers are weaponizing trusted AI platforms.
Huntress SOC: a new attack surface inside trusted AI features
Over the past nine months Huntress has tracked multiple incidents in which threat actors weaponized shareable AI content, public mini‑apps, and sponsored search placement to deliver malware. Rather than compromising underlying AI models or the platform security controls themselves, attackers abused legitimate, shareable features — the very content users recognize and trust.
FakeAgent: a Claude Artifact serving SectopRAT
In July Huntress observed a campaign labeled FakeAgent that hit more than 29 organizations. The campaign began with a malicious Claude Artifact hosted on the real claude.ai domain. Public Artifacts are intended for lightweight demos and receive only minimal vetting from Anthropic beyond a generic disclaimer, and attackers built a convincing fake Claude Desktop download page.
Victims who landed there after searching Bing for the Claude desktop app clicked what appeared to be a legitimate download link and were redirected to an external domain that delivered the SectopRAT malware. Huntress reported the Artifact, and Anthropic removed it by July 22, but Huntress observed incidents tied to the same redirect domain continuing into August.

The cyber insurance questionnaire just landed. Now what?
SOC 2, HIPAA, insurance renewals - someone has to own security strategy. Nubivance provides fractional CISO leadership without the full-time salary.
Get a security leadFake install guide on claude.ai/share delivering MacSync
In a separate incident a sponsored search result for "Claude on Mac" led to a claude.ai/share link posing as an Apple Support install guide. Because the page lived on Anthropic's domain it lacked the usual red flags — no lookalike URL or certificate warning. The guide instructed the victim to paste a curl command into Terminal; that single action kicked off a six‑stage chain that deployed the MacSync stealer.
Huntress reports MacSync harvested cookies, credentials, keychain secrets, Telegram sessions, and SSH and cloud keys, illustrating how a trusted domain plus a clipboard‑driven command can bypass ordinary visual checks.
AI poisoning via ChatGPT and Grok: ClickFix‑style lures and AMOS
Attackers also targeted AI‑generated troubleshooting advice itself. In December a routine search for "clear disk space on macOS" surfaced high‑ranking ChatGPT and Grok conversations that provided ClickFix‑style instructions instead of legitimate fixes. Adversaries crafted the conversations, used the platforms' share functions to create public URLs on chatgpt.com and grok.com, and then applied SEO poisoning to push those links to the top of Google results.
Because the links resided on real chatgpt.com and grok.com domains, users trusted the advice and executed the suggested Terminal commands; those actions delivered the AMOS stealer.
What defenders should do
- Treat clipboard‑driven execution and AI‑assisted troubleshooting as active security risks: restrict script execution from the clipboard and enforce application allow‑listing.
- Monitor for changes attackers typically make after initial compromise: new scheduled tasks and antivirus exclusion changes.
- Train users to recognize ClickFix‑style lures — instructions that promise an instant fix but ask to run pasted commands — and to report suspicious AI‑hosted content to the platform vendor rapidly.
- Use layered controls and fast reporting: Huntress notes these campaigns tend to be short‑lived, so shrinking the window of exposure reduces the number of victims.
What this means for technologists, enterprises, and end users
- Technologists and security teams: prioritize controls that block or log clipboard execution and enforce allow‑listing; watch for post‑infection artifacts Huntress observed, such as task scheduler changes and AV exclusions.
- Enterprises and procurement leaders: review assumptions that hosting on a trusted domain equals safety — public share features can surface in search and be used in malvertising chains that start with sponsored results.
- End users: treat shared AI content with the same suspicion you would a random forum post; commands pasted from a web page — even on a familiar domain — can initiate multi‑stage malware chains.
Huntress's record over the past nine months shows a repeatable pattern: adversaries use legitimate, shareable AI features and search engine mechanics to insert malicious steps into everyday workflows. The root technical failures were not in the platforms' core security, according to Huntress; they were in trust placed in familiar domains and in the ease of executing clipboard‑pasted commands. Fast reporting to vendors and layered local controls are the immediate countermeasures Huntress recommends — but the larger question remains: how will platform sharing features and search ranking mechanisms evolve to reduce the appeal of these short‑lived, high‑impact lures?




