Threat Actors Abuse Trusted AI Platforms (Claude, ChatGPT, Grok) to Distribute Malware — Threadlinqs Intelligence
As of 2026-08-29, Threat Actors Abuse Trusted AI Platforms (Claude, ChatGPT, Grok) to Distribute Malware is a high-severity malware threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 27 indicators of compromise.
Threat ID: TL-2026-2197 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Huntress documents three distinct, ongoing campaigns that abuse the trusted domains of Claude.ai, ChatGPT, and Grok to deliver malware: a 'FakeAgent' malvertising campaign that hosted a fake Claude
This is a technique-driven campaign cluster, not a single vulnerability: threat actors are weaponizing the fact that claude.ai, chatgpt.com, and grok.com are trusted, certificate-valid, un-blockable domains. Because the malicious content lives on the AI vendor's own domain (a public Claude Artifact, a claude.ai/share conversation, or a shared ChatGPT/Grok conversation), victims never see a lookalike domain or certificate warning, which defeats the usual visual heuristics defenders and users rely on.
Three sub-campaigns, all reported by Huntress between July and August 2026, share this technique: (1) FakeAgent — a Bing-sponsored ad for 'Claude Desktop app' led to a public Claude Artifact impersonating the Claude Desktop/Cowork download page; the download button chained through claude.ai.download-app[.]us and downloading-api[.]it[.]com to deliver a renamed JetBrains helper binary that DLL-sideloaded a VMProtect-packed loader (libcef.dll) and ultimately an obfuscated SectopRAT (ArechClient2) .NET RAT/stealer. The operator used Ethereum blockchain transactions ('EtherHiding') for takedown-resistant C2 rotation and GPU/DXGI-based anti-VM checks plus DirectX-shader-based payload decryption. The artifact received 7,100 views and impacted 29 organizations before Anthropic removed it. (2) MacSync — a victim searching Google for how to install Claude on a Mac clicked a sponsored result that led to a claude.ai/share conversation spoofed to look like an Apple Support install guide, instructing the victim to paste a curl command into Terminal. This kicked off a six-stage kill chain: a polymorphic zsh loader, an in-memory bridge stage, a ~46KB server-side AppleScript stealer that social-engineers Full Disk Access and harvests browser Safe Storage keys, keychain secrets, SSH/cloud credentials (~/.ssh, ~/.aws, ~/.kube) and the full Telegram Desktop tdata/ session, a persistent C++ Mach-O RAT installed as a LaunchAgent masquerading as a legitimate updater, a separately signed helper that abuses the macOS Screen Recording TCC permission, and a set of trojanized Ledger/Trezor wallet-companion apps that phish BIP39 seed phrases through fake recovery-error UI. CIS/MS-ISAC subsequently reported the same MacSync family actively targeting US SLTT government macOS users, sharing over 1,000 related IOCs. (3) AI-Poisoning/AMOS — attackers craft a ChatGPT or Grok conversation that ends in a plausible 'fix' for common macOS troubleshooting queries (e.g. 'clear disk space on macOS'), share it to get a public URL on the AI vendor's own domain, and SEO-poison that URL to the top of Google results. The Terminal command silently validates the victim's password via `dscl -authonly`, escalates privileges through `sudo -S` with the password piped via stdin, drops a hidden Mach-O payload, trojanizes any installed Ledger/Trezor apps, and persists via a LaunchDaemon-driven watchdog that relaunches the payload under the active GUI session. Cato Networks separately reported a closely related fake OpenAI Codex 'download' hosted on Google Sites using the same ClickFix pattern (Terminal command, `xattr -c`, execution from /tmp/helper) to deliver an AMOS variant. All three sub-campaigns are ongoing as of the August 27, 2026 Huntress report and are financially motivated, with a heavy emphasis on cryptocurrency wallet and browser-credential theft.
Target sectors: government administration, technology, financial services
Target regions: united states of america
Timeline
- Earliest identified Ethereum BSC transaction used for SectopRAT/FakeAgent 'EtherHiding' C2 rotation.
- Huntress and Kaspersky report the ChatGPT/Grok shared-conversation AMOS stealer campaign has been active since December, ahead of wider August 2026 disclosure.
- MacSync wallet seed-phrase exfiltration domains sdhomeinspectors[.]com and southcarolinacounselor[.]com registered via Unstoppable Domains.
- claude.ai.download-app[.]us redirect domain registered for the FakeAgent/SectopRAT campaign.
- MacSync's Mach-O RAT binary compiled with statically linked OpenSSL 3.6.2 (build timestamp recovered during reverse engineering).
- FakeAgent malvertising campaign begins distributing via Bing-sponsored 'Claude Desktop app' search ads.
- Huntress SOC detects the malicious Claude Artifact, reports it to Anthropic, and it is removed after 7,100 views across 29 impacted organizations.
- Huntress investigates a MacSync intrusion originating from a victim's Google search for Claude-on-Mac install instructions leading to a spoofed claude.ai/share 'Apple Support' guide.
- Huntress publishes a full reverse-engineering breakdown of the six-stage MacSync stealer/RAT kill chain and its IOCs.
- CIS/MS-ISAC publishes an advisory on the MacSync stealer campaign actively targeting U.S. SLTT government macOS users, sharing over 1,000 related IOCs.
- Cato Networks discloses a related fake OpenAI Codex ClickFix campaign hosted on Google Sites that delivers an AMOS stealer variant.
- Huntress publishes 'The AI Attack Surface,' consolidating the FakeAgent, MacSync, and AMOS/AI-poisoning campaigns into a single trend report.
Detections & IOCs
As of 2026-09-06, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 27 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, T1566.002, T1204.001, T1059.004, T1059.002, T1543.001, T1574.001, T1036.005, T1027, T1548, T1070.004