Attackers Abuse Claude Artifacts and ChatGPT Links to Spread Malware
Threat actors are exploiting legitimate features of trusted AI platforms—including Claude Artifacts, shareable claude.ai URLs, and indexed ChatGPT and Grok conversations—to deliver malware under the cover of recognisable branding. The FakeAgent campaign, tracked by Huntress, struck over 29 organisations in July by hosting malicious content directly on the claude.ai domain, where minimal vetting and high user trust create an effective delivery vector. These campaigns are typically short-lived but effective, underscoring how AI platform trust boundaries are being systematically weaponised.