- Huntress detects Claude Artifact malware usurping Claude Desktop and spreading SectopRAT malware
- Victims were redirected via Bing ads, infecting at least 29 organizations between July 21 and 22, 2026.
- Claude deleted the artifact after more than 7,000 views; Malvertising risks persist despite artifact warnings
At least 29 organizations were infected with a remote access Trojan (RAT) after mistaking a public Claude artifact for a legitimate Claude page.
A Claude artifact is an interactive document, or piece of code, that the AI generates and then hosts on the Claude platform. It can then be shared with others as an example or proof of concept for different solutions. The link to an artifact usually looks like this:
Claude[.]ai/public/artifacts/ca466f1f-21c0-42af-b329-8f1c7534a891
Latest videos fromTechRadar
Claude artifacts are often used for phishing and other forms of scams, and we’ve seen this in ClickFix attacks in the past. Claude responded by adding a disclaimer to each artifact, stating that the content is user-generated and therefore not verified.
In this particular case, a malicious artifact was created to spoof the Claude Desktop download page. Victims would be redirected to a domain controlled by the attacker, where, instead of the Claude application, they would download SectopRAT, a remote access Trojan capable of stealing credit card data, personal information, files, passwords, etc.
The artifact was then promoted on Bing, appearing at the very top of search results for people searching for “Claude Desktop App.”
For years, the cybersecurity community has warned about malvertising, urging users to double-check the domain before clicking on links, even promoted ones. However, the problem here is that the advertisement leads victims to Claude’s legitimate domain, making scrutiny even more difficult.
The campaign was spotted by security researchers Huntress, who said that between July 21 and 22, 2026, their SOC “lit up with a series of unusual executable installations, exclusions from Defender, and abnormal persistence across 29 organizations, all originating from ClaudeDesktop.exe.”
Claude has since deleted the malicious artifact, but not before it garnered over 7,000 views. It is possible that other organizations, outside of Huntress’s field of vision, were also victims of this scam.
The best antivirus for every budget
Follow TechRadar on Google News And add us as your favorite source to get our news, reviews and expert opinions in your feeds.




