Fake Claude AI installer abuses DLL sideloading to deploy PlugX
ID: 12357846-17d3-59b8-9d8f-e375c9261d94
STIX ID: report--12357846-17d3-59b8-9d8f-e375c9261d94
Feed Name: Security Affairs
Threat Score
**Executive summary:** A fake Anthropic Claude website distributed a trojanized “pro” installer inside a ZIP that uses DLL sideloading of a legitimately signed G DATA updater to deploy the PlugX RAT (files: NOVUpdate.exe, avk.dll, encrypted .dat); the dropper persists via the Startup folder, self-deletes to evade analysis, and the malware quickly connects to a C2 (8.217.190.58) over HTTPS—IOCs and technique mapping (MITRE T1574.002) are provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
