logo

Fake Claude Campaign Deploys Malware Through DLL Sideloading Chain

ID: ea77296c-ef37-5f6d-b083-fb7dc11a0cb6

STIX ID: report--ea77296c-ef37-5f6d-b083-fb7dc11a0cb6

Feed Name: Cyber Press

Threat Score
72/100

Date Published: 2026-05-11

Date Updated: 2026-05-22

Author: Varshini

...
...

Attackers are distributing a trojanized Windows installer from a fake Claude site (claude-pro.com) that contains an MSI which drops NOVupdate.exe (a signed G DATA updater), a malicious avk.dll, and an encrypted payload. The chain abuses DLL sideloading to run shellcode that launches DonutLoader and installs a newly documented backdoor called Beagle; researchers found related samples reusing an XOR key and domains spoofing major security brands, suggesting a multi-lure campaign likely delivered via malvertising or poisoned search results.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.