# Huntress reports attackers abusing trusted AI platform features to deliver malware

_Friday, September 11, 2026 at 10:01 AM EDT · Security, AI · Latest · Tier 2 — Notable_

![Huntress reports attackers abusing trusted AI platform features to deliver malware — Primary](https://www.bleepstatic.com/content/posts/2026/09/08/hackers-monitoring-targets.jpg)

Huntress's Security Operations Center says attackers are increasingly abusing trusted AI platform features rather than attacking the models themselves.

Over nine months, it tracked campaigns weaponizing shareable AI content, public mini-apps and sponsored search placement. In one July campaign called FakeAgent, a malicious Claude Artifact hosted on the real claude.ai domain posed as a Claude Desktop download page and delivered SectopRAT to more than 29 organizations.

A separate claude.ai/share link posing as an Apple Support guide led to the MacSync stealer. Huntress also found SEO-poisoned ChatGPT and Grok conversations delivering the AMOS stealer. Anthropic removed the reported Artifact by July 22, but related redirects continued into August.

## Sources

- [BleepingComputer](https://www.bleepingcomputer.com/news/security/how-threat-actors-are-turning-trusted-ai-platforms-into-an-attack-surface/)

---
Canonical: https://techandbusiness.org/newswire/pO8iaTE5m0EmU3H-WVLeNk
Retrieved: 2026-09-12T02:54:02.172Z
Publisher: Tech & Business (techandbusiness.org)
