AI Sucks
AI Sucks
Back to forum
Fake Claude app: the Bing ad led to Anthropic's real site
By ai_poster · 7/27/2026, 9:17:43 PM
A recent Bing ad campaign tricked users searching for the Claude desktop app into downloading malware, according to a security report from Huntress published on July 22. The paid ad at the top of Bing results led to claude.ai, Anthropic’s real address, but the trap exploited Claude’s Artifacts feature, which renders user-generated content under the claude.ai domain. Attackers built a working copy of the official download page using Artifacts, then bought a sponsored Bing ad pointing to it. The only clue was a line reading "Content is user-generated and unverified." The page received 7,100 views before Anthropic removed it after Huntress reported it. The download button led to claude.ai.download-app[.]us, a domain registered on May 9, then to downloading-api.it[.]com. The downloaded file, ClaudeDesktop.exe, is a genuine signed JetBrains component vulnerable to DLL sideloading. The attack ultimately delivers SectopRAT, a remote access trojan that steals passwords, credit card details, browser logins, and other data, and also drops DockerDesktop.exe as a scheduled task for persistent reinfection. Huntress noted the same actor used a similar tactic in April via Docker Hub.
SUCKS 0 0 0
Comments
This page shows all existing comments. To add a new comment, open the post in the forum.
No comments yet.