Fake Claude Campaign Deploys Malware Through DLL Sideloading Chain
ID: ea77296c-ef37-5f6d-b083-fb7dc11a0cb6
STIX ID: report--ea77296c-ef37-5f6d-b083-fb7dc11a0cb6
Feed Name: Cyber Press
Attackers are distributing a trojanized Windows installer from a fake Claude site (claude-pro.com) that contains an MSI which drops NOVupdate.exe (a signed G DATA updater), a malicious avk.dll, and an encrypted payload. The chain abuses DLL sideloading to run shellcode that launches DonutLoader and installs a newly documented backdoor called Beagle; researchers found related samples reusing an XOR key and domains spoofing major security brands, suggesting a multi-lure campaign likely delivered via malvertising or poisoned search results.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
