About

The consultancy born at the intersection of behavioral economics and human experience.

NOW HIRING

Join a team reshaping how the world experiences brands.

View open roles →

COMPANY

GROW WITH US

CONNECT

Services

Comprehensive CX and management consulting for enterprise brands.

ALL SERVICES

Explore the full range of CX & management consulting services.

Browse all services →

CORE

SPECIALIST

Solutions

Structured solutions that turn CX ambition into measurable outcomes.

ALL SOLUTIONS

Explore every CX solution we offer.

Browse solutions →

STRATEGY & GOVERNANCE

DESIGN & DELIVERY

CULTURE & EXPERIENCE

Industries

A decade of CX transformation across the region's defining sectors.

ALL INDUSTRIES

See how we work across every sector.

Browse industries →

BUILT ENVIRONMENT

FINANCE & TECH

PEOPLE & MOBILITY

Products

Proprietary tools, platforms, and AI that power CX transformation.

ALL PRODUCTS

Explore the full Renascence product ecosystem.

Browse products →

AI & TECHNOLOGY

LEARNING & GAMES

PLATFORMS & TOOLS

AI PRODUCTS

Opinion

Insights, research, and conversations at the frontier of CX.

ReadExperience JournalArticles & research on CX, behavior, and transformation.
Watch & listenExperience LoomThe Naked Customer — our video podcast on CX & behavior.
CuratedCX NewsIndustry news filtered for what matters in CX — free of the noise.

Hub

Free tools, templates, and resources to advance your CX practice.

NEW · MANIFESTO

Burn the Deck. Ten Virtues. Zero Excuses. — read our manifesto for the brave consultant.

Start reading →

AI TOOLS

FREE TOOLS

LEARNING

CULTURE

Digital Transformation · July 25, 2026

Claude.ai Malware Attack: RAT Hidden in Anthropic Artifacts

Threat actors exploited Anthropic's Claude Artifacts feature to host a remote access trojan on the trusted claude.ai domain, bypassing reputation-based filters and exposing brands to inherited platform risk.

R
Renascence Newsdesk
Curated briefing · 2 min read

What happened

Security researchers have identified a campaign in which threat actors exploited Anthropic's Claude Artifacts feature to host and distribute malware, specifically a remote access trojan (RAT), by embedding it within a page served from the legitimate claude.ai domain. Because the malicious content appeared to originate from a trusted, well-known AI platform, conventional domain-reputation filters were largely ineffective at flagging it.

Claude Artifacts — a feature that allows users to generate and share self-contained interactive content — has now been implicated in phishing-related abuse on more than one occasion. In this instance, attackers used the capability to craft a convincing lure that directed victims toward a payload capable of granting remote control of an infected machine.

Why it matters

For customer-experience and service-design professionals, this incident is a sharp reminder that trust is infrastructural. Organisations increasingly embed AI-generated content — summaries, interactive tools, personalised outputs — directly into customer-facing journeys. When the underlying platform's domain becomes a vector for attack, the reputational and experiential damage extends well beyond the security team: customers who encounter a malicious artefact while engaging with a brand's AI-assisted service will associate the harm with the brand, not the platform.

From a behavioural-economics standpoint, this exploit is a textbook manipulation of authority bias. A URL containing a recognised, even prestigious, domain name suppresses scepticism and accelerates compliance — exactly the cognitive shortcut that phishing campaigns are designed to exploit. As AI-generated interfaces proliferate across service touchpoints, the attack surface for social engineering grows proportionally, and the psychological defences customers rely on become less reliable.

By the numbers

  • At least two separate campaigns have now been documented in which Claude Artifacts was used as a phishing or malware-delivery mechanism, according to reporting by TechRadar.

The Renascence take

Most commentary on this story will focus on Anthropic's platform controls or enterprise security policy. What the conversation tends to miss is the experience-layer vulnerability: the moment a brand delegates any customer interaction to a third-party AI platform, it implicitly borrows that platform's trust equity — and inherits its threat surface.

The deeper issue here is not a security patch away. Organisations that embed AI tools into customer journeys are, behaviourally speaking, asking customers to extend their trust transitively — from the brand to the platform and back again. When that chain breaks, it is the brand relationship that suffers most. Customer-obsessed operators should be conducting explicit AI-vendor trust audits right now: mapping every point where a third-party AI domain touches a customer, assessing what a compromise at that point would look and feel like to the person on the other end, and building transparent fallback communications for when things go wrong. Security resilience and experience resilience are no longer separate disciplines.

Sources

This briefing was written by the Renascence newsdesk, synthesising reporting from the outlets below. Follow the links for the original coverage.

Stay ahead of CX

Get the signal, not the noise.

The stories shaping customer experience — plus the Journal and Experience Loom — in your inbox.