Criminals Are Hiding Malware Inside Trusted AI Tools Like Claude and ChatGPT

Attackers have started using Claude Artifacts, shared ChatGPT links and sponsored AI search results to slip malware past users who trust the branding.

ThreatVectr Newsdesk· 4 min read
Full-frame photoreal editorial shot of a modern server room aisle at night, rows of dark racks with soft blue and amber status lights receding into the distance
Share

Key points

  • Security firm Huntress has documented criminals abusing Claude Artifacts, shared AI chat links, sponsored search ads and fake AI download pages to distribute malware in 2024 and 2025.
  • The trick works because victims trust the AI vendor's domain, so a malicious payload hosted on it inherits that trust.
  • Attackers are also using ClickFix lures, fake error pop-ups that instruct the user to paste a command into Windows, styled to look like AI tool support pages.
  • Search engines are showing sponsored links for terms like "ChatGPT download" that lead to lookalike sites installing infostealers.
  • Ordinary users should install AI tools only from the vendor's own site and never paste commands a web page tells them to run.

Criminals have found a new place to hide their malware: inside the AI platforms people already trust.

Researchers at Huntress, whose findings were first reported by BleepingComputer, describe several ongoing campaigns that abuse Anthropic's Claude, OpenAI's ChatGPT and the search ads around them to trick people into installing malicious software.

The common thread is simple. If a link starts with claude.ai or chatgpt.com, most people click without thinking. Attackers know this, and they are building lures that live on those exact domains.

How are the attackers using Claude and ChatGPT to spread malware?

They are hiding malicious content inside features that are supposed to make AI more useful: shareable chats and interactive artifacts.

Claude has a feature called Artifacts, which lets a user generate a small web app or document inside a chat and share it with a public link. Huntress found attackers building weaponised Artifacts: pages that look like a helpful tool but push the visitor toward downloading malware or handing over credentials, meaning usernames and passwords.

Shared ChatGPT and Claude conversations are being abused the same way. A criminal seeds a chat with plausible-looking instructions, a fake support script, or a download link, then shares the conversation URL in forums and comments. To the victim, it looks like a real AI answer on a real AI site.

This is not a new class of attack. It is the same open-redirect and trusted-host abuse pattern that plagued Google Docs and Dropbox for a decade, applied to a new set of brands.

What is the ClickFix trick, and why does it work?

ClickFix is a lure that shows the victim a fake error message and tells them the fix is to open Windows, paste a command, and press Enter. That command silently installs malware.

Huntress is seeing ClickFix pages dressed up as AI tool support screens: a "verify you are human" box, a fake Cloudflare check, or a phoney ChatGPT loading error. The instruction always ends the same way, with the victim running a PowerShell command that pulls down an infostealer, malware that scoops up saved passwords, browser cookies and cryptocurrency wallets.

The attack works because it turns the victim into their own attacker. No software flaw is exploited. The user is walked, step by step, into infecting their own machine.

How are sponsored search results part of this?

Attackers are buying search ads for terms like "ChatGPT download" and "Claude desktop", so their fake sites appear above the real ones.

The landing pages are pixel-perfect clones of the vendor sites, with a download button that delivers a trojanised installer instead of the real app. Because the ad shows a legitimate-looking display URL, and because there is no official ChatGPT desktop installer for many users to compare against, the ruse holds up long enough to get the click.

Lure Where it lives What the victim gets
Weaponised Claude Artifact claude.ai subdomain Credential phishing or malware link
Shared AI chat link chatgpt.com, claude.ai Fake instructions, malicious download
Sponsored search ad Google results page Lookalike site, trojanised installer
ClickFix pop-up Attacker site styled as AI tool PowerShell command, infostealer

What should ordinary users do?

Treat AI-branded links and downloads with the same suspicion you would give any other. Type the vendor's address into the browser yourself rather than clicking an ad. If any web page ever tells you to open Windows and paste a command, close the tab. Real software never asks for that.

Common questions

Is Claude or ChatGPT itself hacked?

No. The AI platforms are working as designed. Criminals are abusing legitimate sharing features to host bad content on trusted domains, the same way they have long abused Google Drive and Dropbox links.

How do I know if I fell for a ClickFix page?

If you pasted a command into the Windows Run box or PowerShell after visiting a suspicious page, assume your saved browser passwords and session cookies are stolen. Change important passwords from a different device and turn on multi-factor authentication, an extra login code, wherever you can.

© 2026 Threat Vectr