Official Claude Domain Became the Lure

Attackers flipped the usual trust test. A page on claude.ai looked like a real Claude download path, so users who trusted the vendor domain and a search ad were both steered into the trap. Anthropic’s Claude Artifacts feature lets users publish full web pages to public links. Huntress says attackers used that to host a spoofed Claude desktop download page on claude.ai, redirected victims from a sponsored Bing result, and compromised employees at at least 29 organizations in July; the page was viewed 7,100 times before removal. The sharp part is that the malicious page lived inside the official domain, not on some throwaway lookalike site. That breaks the common habit of treating vendor domains as safe and ads as the only thing to inspect, because the first trusted hop can already be hostile.

Part of the PlainSec briefing for 2026-07-23

Sources