UK’s trusted IT infrastructure partner since 2003
Servnet
FinanceToolsConfiguratorGet in Touch
Cyber security

AI Platform Attack Surface 2026: What UK Teams Must Audit

London · Servnet News Desk · IT infrastructure analysis4 min read
Share

Threat actors have found a shortcut past user suspicion: abusing trusted platform features and share links on Claude, ChatGPT and Grok's own domains to host social-engineering lures, poisoned conversations and, in some cases, malware. Huntress Labs' Security Operations Centre says the danger isn't the AI models themselves but the trust users place in genuine platform domains — a distinction that attack surface management strategies for shadow AI usage should now cover.

Nine months of AI-platform abuse tracked by Huntress
W0W7W14W21W28W35W39AI-poisoned ChatGPT/Grok…4wFakeAgent Claude Artifact…3wRedirect domain activity…5wTotal: 39 weeks end-to-end
View the data behind this chart
Nine months of AI-platform abuse tracked by Huntress
PhaseStarts (week)Duration (weeks)
AI-poisoned ChatGPT/Grok…04
FakeAgent Claude Artifact…303
Redirect domain activity…335

Why this matters for UK buyers now

For nine months, Huntress has tracked attackers abusing legitimate, real-domain AI features — not breaking into the platforms, but exploiting the trust that users already place in claude.ai, chatgpt.com and grok.com.

That distinction matters for procurement and risk registers. A phishing page on a lookalike domain triggers browser warnings and staff suspicion. A malicious page hosted on the genuine claude.ai domain, or a poisoned troubleshooting thread ranking on chatgpt.com, may carry fewer of the usual red flags than a typical phishing page — as Huntress found with its claude.ai/share and AI-generated troubleshooting examples. For UK organisations that have quietly let staff adopt Claude, ChatGPT or Grok for coding help, troubleshooting or research without a formal usage policy, this is the moment to treat those platforms as part of the corporate cyber security services perimeter, not outside it.

Three campaigns Huntress documented

The first, dubbed FakeAgent, hit more than 29 organisations in July after attackers published a malicious Claude Artifact that mimicked a Claude Desktop download page. Victims searching Bing for the Claude desktop app clicked through and were redirected to an external domain delivering SectopRAT malware. Huntress reported it and Anthropic removed the Artifact by 22 July, though incidents tied to the same redirect domain kept surfacing into August.

The second used a claude.ai/share link disguised as an Apple Support install guide, surfaced via a sponsored Google result for "Claude on Mac". Because the page sat on Anthropic's own domain, it did not present the obvious lookalike-URL warning that a spoofed domain would. It walked victims through pasting a curl command into Terminal, kicking off a six-stage chain that deployed the MacSync stealer and harvested cookies, credentials, keychain secrets, Telegram sessions, and SSH and cloud keys.

The third pattern targeted AI-generated advice itself. In a December search for "clear disk space on macOS" surfaced high-ranking ChatGPT and Grok conversations giving ClickFix-style instructions rather than genuine fixes. Attackers had generated the conversations, published them via each platform's own share function, then used SEO poisoning to push the links to the top of Google results, ultimately delivering the AMOS stealer.

A pattern bigger than one vendor

This isn't isolated to Anthropic. Microsoft has separately warned that poisoned search results and AI-chatbot interactions are steering users toward malicious download sites. In a related campaign, Microsoft also flagged spoofed utility sites using DLL sideloading chains to install remote-access tooling such as ScreenConnect, and in some cases cryptojacking payloads. Google Discover has also been implicated in AI-generated social-engineering content used to push scareware and ad-fraud pages.

Some browser vendors are already reacting: Opera has shipped a clipboard-command mitigation called Paste Protect designed to help block ClickFix-style abuse. For UK buyers, that's a signal the industry accepts this as a durable threat category rather than a one-off campaign, and that endpoint-level controls, not just user awareness, need to be part of the response alongside endpoint security solutions.

Illustration: AI Platform Attack Surface 2026: What UK Teams Must Audit

Vendor governance is now a security question, not just a procurement one

Anthropic's own platform decisions this year add further weight to treating AI vendors as part of the supply chain risk conversation. AI vendors are actively adjusting access, billing and governance policies, and those changes deserve the same scrutiny as any other supplier relationship.

For UK security leads, the underlying point stands regardless of the specific policy change: the platforms your teams rely on daily are themselves evolving their access, billing and governance terms through 2026, and those changes need tracking with the same discipline as any other zero trust vendor review.

What UK defenders should actually do

None of the three campaigns Huntress documented broke through AI platform security controls. They exploited user trust in familiar branding and genuine domains, which means conventional URL-checking training won't catch them. Defenders need to shift focus to what happens after a link is clicked, particularly around clipboard-driven command execution.

Huntress recommends restricting script execution triggered from the clipboard, enforcing application allow-listing, and watching for new scheduled tasks or antivirus exclusion changes that often accompany these infections. Staff should be trained specifically to recognise ClickFix-style lures that ask them to paste commands into Terminal or PowerShell, and any suspicious AI-hosted content should be reported to the platform vendor immediately, since these campaigns are typically taken down within hours or days. Building that reporting habit into existing managed detection and response workflows closes the gap faster than waiting for the vendor to notice independently.

Share
Key takeaways
  • Attackers are hosting malware and phishing lures on genuine claude.ai, chatgpt.com and grok.com domains, bypassing normal lookalike-URL red flags.
  • A single Claude Artifact campaign, FakeAgent, hit more than 29 organisations in July via a fake desktop download page delivering SectopRAT.
  • A claude.ai/share link posing as Apple Support support content ran a six-stage chain deploying the MacSync stealer, harvesting credentials and cloud keys.
  • UK teams should restrict clipboard-triggered script execution, allow-list applications, and train staff to spot ClickFix-style Terminal command lures.
Frequently asked

FAQs — AI Platform Attack Surface 2026

What is the FakeAgent campaign?

FakeAgent was a July campaign identified by Huntress in which attackers published a malicious Claude Artifact on the real claude.ai domain, mimicking a Claude Desktop download page. It hit more than 29 organisations before redirecting victims to a domain delivering SectopRAT malware; Anthropic removed the Artifact by 22 July, though related incidents continued into August.

How did the claude.ai/share Apple Support scam work?

A victim searching Google for "Claude on Mac" clicked a sponsored result leading to a claude.ai/share link disguised as an Apple Support install guide. Because it sat on Anthropic's genuine domain, it did not present the obvious lookalike-URL warning a spoofed domain would, and instructed the victim to paste a curl command into Terminal, triggering a six-stage chain that deployed the MacSync stealer.

Are ChatGPT and Grok also being abused this way?

Yes. Huntress documented poisoned ChatGPT and Grok shared conversations ranking for a routine macOS troubleshooting search, giving ClickFix-style instructions that delivered the AMOS stealer instead of genuine fixes, after attackers used SEO poisoning to push the links up Google's results.

What should UK security teams do first?

Treat AI platform usage as part of the corporate attack surface: restrict clipboard-driven script execution, enforce application allow-listing, monitor for new scheduled tasks or antivirus exclusion changes, and train staff to recognise ClickFix-style Terminal prompts before rolling out or expanding sanctioned Claude, ChatGPT or Grok use.

Related

Turning this into a buying decision?

One conversation with an engineer who's specced this before. No sales script.

Talk to Servnet →

Talk to a UK specialist

Get expert advice or a no-obligation quote — servers, storage, networking, maintenance, finance and cloud. We reply the same working day.

or call 0800 987 4111