LmCast :: Stay tuned in

How Threat Actors Are Turning Trusted AI Platforms Into an Attack Surface

Recorded: Sept. 11, 2026, 2:10 p.m.

Original Summarized

How Threat Actors Are Turning Trusted AI Platforms Into an Attack Surface

News

Featured
Latest

AdaptHealth confirms 4.1 million people exposed in July cyberattack

Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days

Over 36,000 exposed Plex servers vulnerable to recent flaws

New Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM access

How Threat Actors Are Turning Trusted AI Platforms Into an Attack Surface

GitLab urges users to patch max severity path traversal flaw

Learn to use Claude beyond basic prompts with this $20 course bundle

Microsoft fixes Teams, Outlook launch failures on ARM Windows PCs

Tutorials

Latest
Popular

How to access the Dark Web using the Tor Browser

How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11

How to use the Windows Registry Editor

How to backup and restore the Windows Registry

How to start Windows in Safe Mode

How to remove a Trojan, Virus, Worm, or other Malware

How to show hidden files in Windows 7

How to see hidden files in Windows

Webinars
Downloads

Latest
Most Downloaded

Qualys BrowserCheck

STOPDecrypter

AuroraDecrypter

FilesLockerDecrypter

AdwCleaner

ComboFix

RKill

Junkware Removal Tool

Deals

Categories

eLearning

IT Certification Courses

Gear + Gadgets

Security

VPNs

Popular

Best VPNs

How to change IP address

Access the dark web safely

Best VPN for YouTube

Forums
More

Virus Removal Guides
Startup Database
Uninstall Database
Glossary
Send us a Tip!
Welcome Guide

HomeNewsSecurityHow Threat Actors Are Turning Trusted AI Platforms Into an Attack Surface

How Threat Actors Are Turning Trusted AI Platforms Into an Attack Surface

Sponsored by Huntress Labs

September 11, 2026
10:01 AM
0

As AI platforms become part of daily workflows, attackers have found a new way in: the platforms themselves. The Huntress Security Operations Center (SOC) says the bigger day-to-day risk comes from threat actors abusing the AI features people already trust and rely on, rather than attacks on the AI companies or models themselves.
Over the past nine months, Huntress has tracked incidents in which attackers weaponized shareable AI content, public mini-apps, and sponsored search placement to target AI users and deliver malware.
Legitimate features, hijacked
Huntress has observed threat actors abuse a handful of real AI platform features, including:

Claude Artifacts: content Claude generates and displays in a chat preview pane, which users can publish and share via a public link.

claude.ai/share links: shareable URLs created when someone publishes a Claude conversation; these can surface in search engines when posted to crawlable spots like forums or social media.

ChatGPT and Grok conversations: shared, indexable conversations hosted on chatgpt.com and grok.com that can rank for troubleshooting searches.

Each of these sits inside a trust boundary. Users recognize the platform, the branding, and the surrounding content, so malicious instructions or downloads look legitimate. These campaigns often only run for hours or days before a provider pulls the content down, but that's enough time to trick victims before getting caught.

If you were hit with ransomware, what would you do?
Your files are encrypted, your operations are down, an attacker has named their price, and they're waiting for you to respond. Do you pay? Do you negotiate? Do you even engage at all?
Choose your next move in a simulated ransomware incident, built from tactics Huntress has seen used against real businesses. You'll see how ransomware operators behave when they think they're in control, and what steps you can take for catching an attack before it becomes a negotiation.
Try the Simulator →

FakeAgent: malvertising through a Claude Artifact
In July, Huntress saw a campaign called FakeAgent hit more than 29 organizations. It started with a malicious Claude Artifact hosted on the real claude.ai domain.
Since public Artifacts are meant for lightweight demos and get minimal vetting from Anthropic beyond a generic disclaimer, attackers built a convincing fake Claude Desktop download page.
Victims searching Bing for the Claude desktop app landed on the fake page and clicked what looked like a legitimate download link. Instead, they were redirected to an external domain that delivered the SectopRAT malware.
Huntress reported the Artifact and Anthropic removed it by July 22, but incidents tied to the same redirect domain continued into August.

Figure 1: Claude Desktop/Cowork phishing page hosted as a Claude Artifact.
A fake install guide hiding in claude.ai/share
In a separate incident, a victim searching Google for "Claude on Mac" clicked a sponsored result that led to a claude.ai/share link posing as an Apple Support install guide. Because the page lived on Anthropic's own domain, it carried none of the usual red flags: no lookalike URL, no certificate warning.
The fake guide instructed the victim to paste a curl command into Terminal, kicking off a six-stage chain that deployed the MacSync stealer. It harvested cookies, credentials, keychain secrets, Telegram sessions, and SSH and cloud keys.

Figure 2: The weaponized claude.ai shared conversation, badged as shared by Apple Support,
walking the victim through pasting a curl one-liner into Terminal.
AI poisoning via ChatGPT and Grok
A third pattern targets AI-generated troubleshooting advice itself. In December, a routine search for "clear disk space on macOS" surfaced high-ranking ChatGPT and Grok conversations that gave ClickFix-style instructions instead of real fixes.
Attackers had crafted the conversations, hit "share" to generate a public URL on the platform's trusted domain, and used SEO poisoning to push the link to the top of Google's results.
Because the links lived on real chatgpt.com and grok.com domains, victims trusted the advice and ran the suggested Terminal commands, which delivered the AMOS stealer. 

Figure 3: Top search results and highly rated links via Google Search
What defenders should do
None of these attacks broke through the AI platform security. They exploited the trust users place in familiar brands and real domains. 
Defenders should treat clipboard-driven execution and AI-assisted troubleshooting as security risks. Restrict script execution from the clipboard and enforce application allow-listing. Watch for new scheduled tasks and antivirus exclusion changes, and train users to spot ClickFix-style lures. Report suspicious AI-hosted content to the platform vendor quickly.
These campaigns tend to be short-lived, but fast reporting and layered controls can shrink the window attackers get to exploit them.
If you’re interested in this kind of tradecraft and exploring how attackers evolve their tactics, join our experts at Tradecraft Tuesday, where we break it all down every month. 
Sponsored and written by Huntress Labs.

Artificial Intelligence
Claude
ClickFix
Cybersecurity
Huntress Labs
Phishing

Previous Article

Comments have been disabled for this article.

Popular Stories

Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days

September Windows Server updates break Remote Desktop Services

New Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM access

Sponsor Posts

Find your gaps before an auditor does. Check your EU CRA readiness in 5 questions. 

EtherHiding Malware on macOS: How Attackers Hide C2 on the Blockchain

Stay one step ahead of new threats in the new year. Join Huntress for the monthly Tradecraft Tuesday.

Overdue a password health-check? Audit your Active Directory for free

Follow us:

Main Sections

News
Webinars
VPN Buyer Guides
SysAdmin Software Guides
Downloads
Virus Removal Guides
Tutorials
Startup Database
Uninstall Database
Glossary

Community

Forums
Forum Rules
Chat

Useful Resources

Welcome Guide
Sitemap

Company

About BleepingComputer
Contact Us
Send us a Tip!
Advertising
Write for BleepingComputer
Social & Feeds
Changelog

Terms of Use - Privacy Policy - Ethics Statement - Affiliate Disclosure

Copyright @ 2003 - 2026 Bleeping Computer® LLC - All Rights Reserved

Login

Username

Password

Remember Me

Sign in anonymously

Sign in with Twitter

Not a member yet? Register Now


Reporter

Help us understand the problem. What is going on with this comment?

Spam

Abusive or Harmful

Inappropriate content

Strong language

Other

Read our posting guidelinese to learn what content is prohibited.

Submitting...
SUBMIT

Threat actors are exploiting the trust placed in legitimate AI platforms by turning them into an expanded attack surface, shifting the primary risk from the AI models themselves to the features users interact with daily. Research conducted by the Huntress Security Operations Center indicates that the most significant day-to-day risk stems from threat actors weaponizing shareable AI content, public mini-applications, and sponsored search placements to deliver malware to end-users.

Attackers leverage specific, legitimate platform features to create convincing lures that bypass standard security checks because users inherently trust the branding and context of the AI environment. These exploited features include Claude Artifacts, shareable links from claude.ai/share, and indexable conversations from ChatGPT and Grok. Since these interactions occur within established trust boundaries, malicious instructions or downloads are often perceived as legitimate by the victim. While these campaigns are generally short-lived, the time allotted to tricking victims is sufficient for compromise.

One demonstrated attack vector involved using Claude Artifacts to distribute malware, as seen in the FakeAgent campaign. Attackers created malicious files disguised as legitimate downloads, such as a fake Claude Desktop application, hosted on the official domain. Victims searching for this software would be redirected to external domains, where they were prompted to execute code that deployed malware like SectopRAT. Another method involved weaponizing shared links, where attackers posted content, such as a shared conversation, to search engines, which could surfaced in contexts like forums or social media. These shared links, residing on trusted domains, carried no typical security warnings, tricking users into following instructions, such as pasting command line instructions into a terminal to deploy tools like the MacSync stealer.

A third pattern involves AI poisoning targeting the quality of troubleshooting advice itself. Threat actors craft AI-generated content, such as public troubleshooting guides, and use search engine optimization to ensure these results rank highly. By sharing these conversations on the platform's domains, attackers trick users into trusting the advice and executing suggested commands, which subsequently deploys malware, exemplified by the AMOS stealer.

Defenders must pivot their security strategy to address execution methods and user behavior related to AI assistance. To mitigate this risk, security measures should focus on restricting script execution from the clipboard and enforcing application allow-listing to prevent unauthorized software deployment. Furthermore, monitoring for changes in scheduled tasks and antivirus exclusion policies is necessary. Education is also critical, requiring users to be trained to recognize clickfix-style lures and understand that AI-assisted troubleshooting can be a vector for sophisticated attacks. Prompt reporting of suspicious, AI-hosted content to the respective platform vendors should be prioritized to enable rapid response and shrinking the window of exposure for these transient campaigns.