Executive Summary
In 2026, Huntress Labs documented a sophisticated social engineering campaign where threat actors weaponized trusted AI platforms including Claude, ChatGPT, and Grok to deliver malware. The FakeAgent campaign exploited Claude Artifacts and shared conversation features to create fake download pages and malicious install guides that appeared legitimate due to hosting on trusted domains like claude.ai, chatgpt.com, and grok.com. Over nine months, attackers delivered SectopRAT, MacSync stealer, and AMOS stealer malware to over 29 organizations by abusing shareable AI content and SEO poisoning techniques. This represents a significant evolution in social engineering tactics as attackers leverage the inherent trust users place in established AI platforms to bypass traditional security awareness training and detection mechanisms.
Why This Matters Now
AI platforms are rapidly becoming integral to daily workflows, creating new attack surfaces that exploit user trust rather than technical vulnerabilities. This trend highlights the urgent need for organizations to reassess security controls around AI tool usage and clipboard-driven execution as traditional domain-based trust models become ineffective.
Attack Path Analysis
Attackers exploited trusted AI platforms (Claude, ChatGPT, Grok) by creating malicious shareable content that appeared legitimate due to trusted domains. Victims were lured through SEO poisoning and sponsored ads to fake install guides or troubleshooting advice hosted on legitimate AI platform domains. Once victims executed malicious commands (curl, Terminal scripts), attackers deployed various RATs and stealers (SectopRAT, MacSync, AMOS) to establish persistence and harvest credentials. The malware enabled command and control channels for remote access and data collection. Stolen credentials, cookies, SSH keys, and sensitive data were exfiltrated to attacker-controlled infrastructure. The campaigns achieved significant impact through credential theft, potential lateral movement into corporate networks, and compromise of multiple organizations.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Threat actors created malicious Claude Artifacts, shared ChatGPT/Grok conversations, and claude.ai/share links hosting fake software download pages and install guides on trusted AI platform domains, leveraging SEO poisoning and sponsored search results to lure victims
MITRE ATT&CK® Techniques
Phishing: Spearphishing Attachment
User Execution: Malicious File
Command and Scripting Interpreter: Unix Shell
Process Injection
Masquerading: Match Legitimate Name or Location
Credentials from Password Stores: Keychain
Unsecured Credentials: Credentials In Files
Exfiltration Over C2 Channel
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
CISA Zero Trust Maturity Model 2.0 – User Education and Awareness
Control ID: ID.BE-5
NYDFS 23 NYCRR 500 – Training and Monitoring
Control ID: 500.14
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
PCI DSS 4.0 – Security Awareness Program
Control ID: 12.6.1
DORA – ICT Risk Management
Control ID: Article 13
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer Software/Engineering
High risk from AI platform social engineering attacks targeting developers who rely on trusted AI tools for coding assistance and troubleshooting solutions.
Financial Services
Critical exposure to credential theft and data exfiltration through malicious AI-hosted content, threatening sensitive financial data and regulatory compliance requirements.
Information Technology/IT
Severe impact from weaponized AI platforms delivering malware through trusted domains, compromising IT infrastructure management and security operations workflows.
Health Care / Life Sciences
Significant threat to HIPAA compliance from AI-based social engineering attacks that could compromise patient data through malicious troubleshooting guides.
Sources
- How Threat Actors Are Turning Trusted AI Platforms Into an Attack Surfacehttps://www.bleepingcomputer.com/news/security/how-threat-actors-are-turning-trusted-ai-platforms-into-an-attack-surface/Verified
- FakeAgent: Claude Desktop Malvertising Ends in .NET RAT - Huntress Labshttps://www.huntress.com/blog/fakeagent-claude-desktop-malvertising-ends-in-dotnet-ratVerified
- MacSync Stealer RAT Reverse Engineering - Huntress Labshttps://www.huntress.com/blog/macsync-stealer-rat-reverse-engineeringVerified
- What is AI Poisoning? - Huntress Labs Generative AI Guidehttps://www.huntress.com/generative-ai-guide/what-is-ai-poisoningVerified
- Friendly Prompt is ClickFix Scam - Huntress Labshttps://www.huntress.com/blog/friendly-prompt-is-clickfix-scamVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would have constrained this AI platform attack by limiting lateral movement through network segmentation and reducing blast radius through workload isolation. The fabric's egress controls and east-west traffic enforcement could have significantly reduced the attacker's ability to move between cloud environments and exfiltrate harvested credentials.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Initial workload compromise would likely still occur, but the fabric's segmentation policies could have limited the scope of accessible network resources and cloud services from the compromised endpoint
Control: Zero Trust Segmentation
Mitigation: RAT deployment may have proceeded, but zero trust policies would likely have constrained the malware's ability to access privileged network segments and cloud service endpoints beyond the initially compromised workload
Control: East-West Traffic Security
Mitigation: Lateral movement attempts would likely have been constrained by east-west traffic inspection and policy enforcement, limiting attacker reachability between cloud workloads and sensitive network segments
Control: Multicloud Visibility & Control
Mitigation: C2 communications may have been established, but multicloud visibility would likely have detected and logged anomalous traffic patterns, potentially constraining command execution scope across cloud environments
Control: Egress Security & Policy Enforcement
Mitigation: Data harvesting could have continued, but egress security policies would likely have constrained outbound data flows, potentially limiting the volume and destinations of exfiltrated credentials and sensitive information
Organizational impact would likely have been constrained to isolated network segments, with reduced cross-cloud exposure and limited access to high-value assets protected by segmentation boundaries
Impact at a Glance
Affected Business Functions
- Information Technology Operations
- Security Operations
- End-user Productivity
- Data Protection
Estimated downtime: 2 days
Estimated loss: $50,000
Compromised credentials, browser cookies, keychain secrets, SSH keys, cloud access tokens, Telegram sessions, and potential corporate authentication tokens across 29+ organizations. Data includes login credentials for business applications, cloud services, and development environments.
Recommended Actions
Key Takeaways & Next Steps
- • Implement egress security and policy enforcement to block unauthorized outbound connections from malicious curl commands and RAT communications to external domains
- • Deploy multicloud visibility and control systems to detect anomalous interactions with AI platforms and suspicious automation patterns in user behavior
- • Establish zero trust segmentation with identity-based policies to limit blast radius when credentials are compromised and prevent lateral movement
- • Configure cloud firewall with URL filtering and AI-powered traffic discovery to identify and block access to malicious AI-hosted content and redirect domains
- • Enable threat detection and anomaly response capabilities to baseline normal AI platform usage and alert on suspicious download patterns or terminal execution activities



