HomeIntelligenceBrief
BREACH BRIEF🟠 High Breach

Fake Claude Download Page on claude.ai Domain Leads to SectopRAT Malware Infection Across 29 Organizations

Attackers leveraged Anthropic’s Claude Artifacts feature to host a counterfeit download page that delivered the SectopRAT RAT, compromising employees at 29 firms and exfiltrating sensitive data. The incident highlights the need for robust security‑awareness controls and audit‑ready evidence under SOC 2.

LiveThreat™ Intelligence · 📅 July 24, 2026· 📰 helpnetsecurity.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
3 recommended
📰
Source
helpnetsecurity.com

Fake Claude Download Page on claude.ai Domain Leads to SectopRAT Malware Infection Across 29 Organizations

What Happened — Attackers published a public Claude Artifacts page that mimicked the official Claude desktop‑app download site. When users clicked a sponsored Bing ad and followed the “Download” button, they were redirected to a malicious domain that delivered the SectopRAT remote‑access trojan. Within two days, employees at ≥ 29 organizations were compromised, and the RAT exfiltrated credit‑card data, personal information, and passwords.

Why It Matters for Compliance & Audit Readiness

  • The incident exemplifies a failure of access‑control and user‑awareness policies that SOC 2 expects to be documented, monitored, and tested.
  • Continuous evidence of security‑awareness training and phishing‑simulation results can serve as audit‑ready proof that your organization mitigates social‑engineering risks.
  • Mapping this event to the SOC 2 CC 6.2 (Security Awareness) control helps demonstrate due diligence and a defensible audit trail.

Who Is Affected – AI‑SaaS providers, enterprise users of generative‑AI tools, and any organization that permits employees to download software from web sources.

Recommended Actions

  • Review and tighten web‑download policies; enforce approved‑source whitelisting.
  • Conduct immediate security‑awareness refresher training focused on malicious ads and spoofed download pages.
  • Capture evidence of training completion and phishing‑simulation results for SOC 2 audit artifacts.

Source: Help Net Security

Technical Notes – The malicious artifact redirected to claude.ai.download-app.usdownloading-api.it.com/html/claude/win. The payload bundled a signed JetBrains binary vulnerable to DLL sideloading, a tampered libcef.dll, and a dropped DockerDesktop.exe registered as a scheduled task. The RAT (SectopRAT) harvested credit‑card numbers, credentials, and files. Source: same article

📰 Original Source
https://www.helpnetsecurity.com/2026/07/23/anthropic-claude-artifacts-download-malware/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Security Awareness

Phishing and social engineering are a people-and-policy problem.

The Verisq AI Trust Operations platform pairs Security Awareness Training with policy adoption tracking, so human-risk controls are documented and audit-ready.

Explore the Verisq AI Trust Operations platform →