bleeping-computer · Crawled Sep 11, 2026

How Threat Actors Are Turning Trusted AI Platforms Into an Attack Surface

3 IoCs 2 Malware
Read original article ↗

AI Summary

Threat actors are exploiting trusted AI platforms such as Claude, ChatGPT, and Grok by weaponizing shareable content features to distribute malware. Attackers created malicious Claude Artifacts and shared conversations that mimic legitimate software install guides or troubleshooting advice, hosted on the official domains of these platforms, to bypass user skepticism. These lures trick users into downloading SectopRAT, MacSync stealer, or AMOS stealer via malicious commands or redirects, leveraging the inherent trust in well-known domains. The campaigns are short-lived but effective, relying on SEO poisoning and sponsored search results to increase visibility.

AI-extracted · verify before operational use

Extracted Entities 2 found

Indicators of Compromise 3 extracted

Type Value Detail
Domain claude[.]ai Details →
Domain chatgpt[.]com Details →
Domain grok[.]com Details →

MITRE ATT&CK TTPs 45 techniques

T1001.003 Protocol or Service Impersonation · Command And Control T1014 Rootkit · Defense Evasion T1027 Obfuscated Files or Information · Defense Evasion T1048 Exfiltration Over Alternative Protocol · Exfiltration T1053.005 Scheduled Task · Execution T1059 Command and Scripting Interpreter · Execution T1059.001 PowerShell · Execution T1059.004 Unix Shell · Execution T1071.001 Web Protocols · Command And Control T1071.003 Mail Protocols · Command And Control T1071.004 DNS · Command And Control T1082 System Information Discovery · Discovery T1090 Proxy · Command And Control T1114 Email Collection · Collection T1120 Peripheral Device Discovery · Discovery T1204.002 Malicious File · Execution T1497 Virtualization/Sandbox Evasion · Defense Evasion T1539 Steal Web Session Cookie · Credential Access T1555 Credentials from Password Stores · Credential Access T1003 OS Credential Dumping · Credential Access T1013 T1013 T1016 System Network Configuration Discovery · Discovery T1021.001 Remote Desktop Protocol · Lateral Movement T1055 Process Injection · Defense Evasion T1056.001 Keylogging · Collection T1056.002 GUI Input Capture · Collection T1068 Exploitation for Privilege Escalation · Privilege Escalation T1069.001 Local Groups · Discovery T1070.004 File Deletion · Defense Evasion T1071 Application Layer Protocol · Command And Control T1078 Valid Accounts · Defense Evasion T1078.001 Default Accounts · Defense Evasion T1078.004 Cloud Accounts · Defense Evasion T1083 File and Directory Discovery · Discovery T1086 T1086 T1105 Ingress Tool Transfer · Command And Control T1136.001 Local Account · Persistence T1210 Exploitation of Remote Services · Lateral Movement T1218.011 Rundll32 · Defense Evasion T1485 Data Destruction · Impact T1499.004 Application or System Exploitation · Impact T1543.001 Launch Agent · Persistence T1548.002 Bypass User Account Control · Privilege Escalation T1557 Adversary-in-the-Middle · Credential Access T1566 Phishing · Initial Access