Threat actors have found a shortcut past user suspicion: abusing trusted platform features and share links on Claude, ChatGPT and Grok's own domains to host social-engineering lures, poisoned conversations and, in some cases, malware. Huntress Labs' Security Operations Centre says the danger isn't the AI models themselves but the trust users place in genuine platform domains — a distinction that attack surface management strategies for shadow AI usage should now cover.
View the data behind this chart
| Phase | Starts (week) | Duration (weeks) |
|---|---|---|
| AI-poisoned ChatGPT/Grok… | 0 | 4 |
| FakeAgent Claude Artifact… | 30 | 3 |
| Redirect domain activity… | 33 | 5 |
Why this matters for UK buyers now
For nine months, Huntress has tracked attackers abusing legitimate, real-domain AI features — not breaking into the platforms, but exploiting the trust that users already place in claude.ai, chatgpt.com and grok.com.
That distinction matters for procurement and risk registers. A phishing page on a lookalike domain triggers browser warnings and staff suspicion. A malicious page hosted on the genuine claude.ai domain, or a poisoned troubleshooting thread ranking on chatgpt.com, may carry fewer of the usual red flags than a typical phishing page — as Huntress found with its claude.ai/share and AI-generated troubleshooting examples. For UK organisations that have quietly let staff adopt Claude, ChatGPT or Grok for coding help, troubleshooting or research without a formal usage policy, this is the moment to treat those platforms as part of the corporate cyber security services perimeter, not outside it.
Three campaigns Huntress documented
The first, dubbed FakeAgent, hit more than 29 organisations in July after attackers published a malicious Claude Artifact that mimicked a Claude Desktop download page. Victims searching Bing for the Claude desktop app clicked through and were redirected to an external domain delivering SectopRAT malware. Huntress reported it and Anthropic removed the Artifact by 22 July, though incidents tied to the same redirect domain kept surfacing into August.
The second used a claude.ai/share link disguised as an Apple Support install guide, surfaced via a sponsored Google result for "Claude on Mac". Because the page sat on Anthropic's own domain, it did not present the obvious lookalike-URL warning that a spoofed domain would. It walked victims through pasting a curl command into Terminal, kicking off a six-stage chain that deployed the MacSync stealer and harvested cookies, credentials, keychain secrets, Telegram sessions, and SSH and cloud keys.
The third pattern targeted AI-generated advice itself. In a December search for "clear disk space on macOS" surfaced high-ranking ChatGPT and Grok conversations giving ClickFix-style instructions rather than genuine fixes. Attackers had generated the conversations, published them via each platform's own share function, then used SEO poisoning to push the links to the top of Google results, ultimately delivering the AMOS stealer.
A pattern bigger than one vendor
This isn't isolated to Anthropic. Microsoft has separately warned that poisoned search results and AI-chatbot interactions are steering users toward malicious download sites. In a related campaign, Microsoft also flagged spoofed utility sites using DLL sideloading chains to install remote-access tooling such as ScreenConnect, and in some cases cryptojacking payloads. Google Discover has also been implicated in AI-generated social-engineering content used to push scareware and ad-fraud pages.
Some browser vendors are already reacting: Opera has shipped a clipboard-command mitigation called Paste Protect designed to help block ClickFix-style abuse. For UK buyers, that's a signal the industry accepts this as a durable threat category rather than a one-off campaign, and that endpoint-level controls, not just user awareness, need to be part of the response alongside endpoint security solutions.

Vendor governance is now a security question, not just a procurement one
Anthropic's own platform decisions this year add further weight to treating AI vendors as part of the supply chain risk conversation. AI vendors are actively adjusting access, billing and governance policies, and those changes deserve the same scrutiny as any other supplier relationship.
For UK security leads, the underlying point stands regardless of the specific policy change: the platforms your teams rely on daily are themselves evolving their access, billing and governance terms through 2026, and those changes need tracking with the same discipline as any other zero trust vendor review.
What UK defenders should actually do
None of the three campaigns Huntress documented broke through AI platform security controls. They exploited user trust in familiar branding and genuine domains, which means conventional URL-checking training won't catch them. Defenders need to shift focus to what happens after a link is clicked, particularly around clipboard-driven command execution.
Huntress recommends restricting script execution triggered from the clipboard, enforcing application allow-listing, and watching for new scheduled tasks or antivirus exclusion changes that often accompany these infections. Staff should be trained specifically to recognise ClickFix-style lures that ask them to paste commands into Terminal or PowerShell, and any suspicious AI-hosted content should be reported to the platform vendor immediately, since these campaigns are typically taken down within hours or days. Building that reporting habit into existing managed detection and response workflows closes the gap faster than waiting for the vendor to notice independently.
- 01BleepingComputer — How Threat Actors Are Turning Trusted AI Platforms Into an Attack Surface · 11 September 2026
- 02TechRadar Pro — Microsoft warns AI chatbots may be sending victims to malicious websites · 1 January 2026
- 03The Hacker News — AI recommendation poisoning: how ask-AI features get abused · 1 August 2026
- 04Tom's Hardware — Anthropic blocks Chinese firms from Claude · 1 January 2025
- 05Ars Technica — Claude gained unauthorised access to 3 networks · 1 July 2026
- 06techradar.com
- 07bleepingcomputer.com
- 08arstechnica.com
