logo

Hackers Use PlugX-Like DLL Sideloading Chain in Fake Claude Malware Campaign

ID: e48eb7b7-52e1-5a21-a766-dba981ee13cd

STIX ID: report--e48eb7b7-52e1-5a21-a766-dba981ee13cd

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-05-11

Date Updated: 2026-05-11

Author: Tushar Subhra Dutta

...
...

Researchers observed a malicious campaign hosted on a fake Claude AI site (claude-pro.com) distributing a ZIP with a signed installer that performs DLL sideloading (replacing avk.dll) to load an XOR-encrypted DonutLoader shellcode and deploy a newly identified Beagle backdoor that communicates with license.claude-pro.com using a hardcoded AES key; the report includes IoCs (domains, IPs, filenames, encryption keys), evidence of multiple related samples across 2026, and mitigation advice such as downloading only from official sources and monitoring startup folders and outbound connections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.