Hackers Use PlugX-Like DLL Sideloading Chain in Fake Claude Malware Campaign
ID: e48eb7b7-52e1-5a21-a766-dba981ee13cd
STIX ID: report--e48eb7b7-52e1-5a21-a766-dba981ee13cd
Feed Name: cybersecurityNews.com
Researchers observed a malicious campaign hosted on a fake Claude AI site (claude-pro.com) distributing a ZIP with a signed installer that performs DLL sideloading (replacing avk.dll) to load an XOR-encrypted DonutLoader shellcode and deploy a newly identified Beagle backdoor that communicates with license.claude-pro.com using a hardcoded AES key; the report includes IoCs (domains, IPs, filenames, encryption keys), evidence of multiple related samples across 2026, and mitigation advice such as downloading only from official sources and monitoring startup folders and outbound connections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
