Fake Claude App Hosted on Anthropic Infrastructure Compromises 29 Firms
Hackers exploited Anthropic’s official hosting infrastructure to distribute malware disguised as the Claude desktop application, compromising at least 29 companies between July 21 and July 22, 2026. By utilizing legitimate Anthropic domains, the attackers bypassed standard corporate security filters that typically flag suspicious download sources. This incident highlights a growing vector where attackers turn the trusted infrastructure of AI companies against their own users.
Weaponizing Trusted Domains
The campaign relied on a technique known as trusted-domain hosting, exploiting the public sharing features of Anthropic's platform. Attackers created a malicious page directly on an official Anthropic subdomain. This page presented users with a download link for a simulated 'Claude for Desktop' application.
Because the download URL originated from a verified Anthropic domain, corporate web filters and endpoint protection systems categorized the traffic as safe. Employees seeking the desktop client downloaded a file that appeared legitimate but contained a malicious payload.
The attack chain consisted of several distinct phases:
- Infrastructure Abuse: The threat actors configured a public-facing page on Anthropic's servers, eliminating the need to buy domains or set up hosting.
- Visual Mimicry: The landing page copied Anthropic's design assets, logos, and typography to create a convincing replica of an official download portal.
- Silent Execution: Once downloaded, the installer executed a background script while displaying a fake loading screen to avoid raising suspicion.
The Malware Payload
The fake installer delivered an information-stealing Trojan designed to target corporate credentials, cryptocurrency wallets, and browser cookies. This malware specifically targeted high-value session tokens stored in web browsers.
By harvesting session cookies, attackers can bypass multi-factor authentication (MFA) protocols. Once a session token is stolen, the attacker can clone the user's active session on their own machine, gaining immediate access to internal corporate systems without needing to trigger password alerts or MFA prompts.
Infostealers have become the preferred tool for initial access brokers. Instead of launching immediate ransomware attacks, these brokers collect access credentials and sell them on dark web marketplaces to more sophisticated threat actors.
The Threat of Platform Abuse
AI service providers are increasingly offering tools that allow users to generate, host, and share web applications or code artifacts. While these features facilitate rapid prototyping, they also provide malicious actors with free, highly trusted infrastructure.
Security teams face a difficult challenge when managing these platforms. Whitelisting a domain like claude.ai or its subdomains is common practice to ensure employees can access productivity tools. However, this broad permission allows any malicious content hosted on those same domains to pass through perimeter defenses unchecked.
The rapid adoption of AI assistants has outpaced corporate IT governance. Employees often download tools and browser extensions without official approval, creating a shadow IT environment where malicious software can easily masquerade as productivity enhancers.
To counter this threat, organizations must move away from simple domain-based trust models:
- Full Path Inspection: Network security tools must analyze the complete URL path and file metadata rather than relying on domain reputation alone.
- Endpoint Application Control: IT departments should enforce strict application whitelisting, preventing the execution of unsigned binaries or files downloaded from browser sessions.
- Behavioral Monitoring: Security systems must monitor endpoint behavior for unusual outbound connections or attempts to access local browser credential databases.
Mitigation and Remediation
Anthropic acted quickly to remove the malicious pages and terminate the accounts associated with the campaign. The company has also adjusted its automated abuse detection systems to better identify and block executable files hosted on its sharing platforms.
Despite these actions, the affected companies must now conduct extensive forensic investigations. Because session cookies were compromised, security teams must invalidate all active tokens, force password resets, and audit access logs for unauthorized entry points across all connected SaaS applications.
Security teams must now prepare for a rise in similar abuse campaigns as more AI platforms expand their public hosting and sharing capabilities.
Social Media Planner — LinkedIn, X, Instagram, TikTok, YouTube