How Threat Actors Are Turning Trusted AI Platforms Into an Attack Surface

Trusted AI Platforms Hijacked by Threat Actors, Delivering Malware to Users

A growing trend in cybersecurity threats has come to light as threat actors have begun exploiting trusted artificial intelligence (AI) platforms to distribute malware to unsuspecting users. Rather than targeting the AI companies or models themselves, attackers are leveraging legitimate features and functionality of these platforms to trick victims into downloading malicious software.

This phenomenon is particularly concerning as AI platforms have become an integral part of daily workflows for many individuals and organizations. The reliance on these platforms creates a false sense of security, making it easier for threat actors to manipulate users into divulging sensitive information or installing malware.

At the heart of this issue are legitimate features that sit within a trust boundary. For instance, AI platforms like Claude Artifacts, claude.ai/share links, and shared conversations hosted on chatgpt.com and grok.com have been hijacked by attackers. These features are designed to be shareable, with some even appearing in search engine results when posted to public forums or social media.

The attacks often involve convincing users to download malicious software by disguising it as a legitimate application update or support file. The use of trusted domains and branding makes the malicious content appear authentic, allowing attackers to evade detection for hours or even days before the platform’s provider removes the offending material.

A recent campaign called FakeAgent, which targeted over 29 organizations in July, serves as an example of this tactic. Threat actors created a convincing fake download page for Claude Desktop on the real claude.ai domain, redirecting victims to an external site that delivered the SectopRAT malware. The malicious Artifact was removed by Anthropic on July 22, but incidents tied to the same redirect domain continued into August.

Another incident involved a victim searching Google for “Claude on Mac” and clicking on a sponsored result that led to a claude.ai/share link posing as an Apple Support install guide. This fake guide instructed the user to paste a curl command into Terminal, ultimately deploying the MacSync stealer, which harvested sensitive information from the user’s device.

A third pattern targets AI-generated troubleshooting advice itself. In December, a routine search for “clear disk space on macOS” surfaced high-ranking ChatGPT and Grok conversations that gave ClickFix-style instructions instead of real fixes. Attackers had crafted these conversations to include malicious links, which were then pushed to the top of Google’s results using SEO poisoning.

To mitigate this risk, defenders should treat clipboard-driven execution and AI-assisted troubleshooting as security risks. Restricting script execution from the clipboard and enforcing application allow-listing can help prevent attacks. Additionally, monitoring for new scheduled tasks and antivirus exclusion changes is crucial in detecting potential threats.

Ultimately, the hijacking of trusted AI platforms by threat actors serves as a reminder that even the most secure systems can be vulnerable to manipulation. By being aware of these tactics and taking proactive measures to protect against them, organizations can reduce their exposure to these types of attacks.


Source: Bleeping Computer — 2026-09-11