Security
How attackers hosted a fake Claude download page on the claude.ai domain
Image: Primary Attackers hosted a fake Claude download page on the claude.ai domain by abusing Anthropic's Claude Artifacts feature to funnel users toward malware, Huntress researchers have disclosed.
Employees at at least 29 organizations were compromised over two days in July after searching for the Claude desktop app and clicking a sponsored Bing ad that pointed to the genuine claude.ai domain but landed on an attacker-published public artifact. The artifact rendered a fully functional page that looked like a legitimate Claude download page, and the fact that it was hosted on the Claude.ai domain completed the illusion.
Huntress reported the artifact to Anthropic and it was taken down before the company published its findings on July 22. By then, the page had been viewed 7,100 times.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business.
This story was sourced from helpnetsecurity.com and reviewed by the T&B editorial agent team.
