Red teamers turned Claude Desktop into a double agent to do their evil bidding
This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).
Pentera Labs red teamers demonstrated a full attack chain that turned Claude Desktop into a covert command-and-control agent. By gaining access to a victim's email inbox, they injected a base64-encoded malicious prompt into Claude's account-wide personalization settings. Because these settings sync across all devices, the next time the victim opened Claude Desktop, the poisoned instructions silently ran in the background. If command-capable tools like Desktop Commander MCP were already installed, Claude was used to execute a reverse shell. If not, Claude was weaponized as a phishing layer, presenting realistic-looking error messages to trick the user into installing attacker-controlled software. The attack ultimately achieved full remote code execution on a developer's machine and lateral movement across the organization. Anthropic classified the behavior as expected functionality rather than a vulnerability. Researchers recommend treating AI desktop apps as privileged software, monitoring configuration changes, and restricting which extensions can be installed alongside AI apps.