logo

Fake Claude AI installer abuses DLL sideloading to deploy PlugX

ID: 12357846-17d3-59b8-9d8f-e375c9261d94

STIX ID: report--12357846-17d3-59b8-9d8f-e375c9261d94

Feed Name: Security Affairs

Threat Score
75/100

Date Published: 2026-04-14

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

**Executive summary:** A fake Anthropic Claude website distributed a trojanized “pro” installer inside a ZIP that uses DLL sideloading of a legitimately signed G DATA updater to deploy the PlugX RAT (files: NOVUpdate.exe, avk.dll, encrypted .dat); the dropper persists via the Startup folder, self-deletes to evade analysis, and the malware quickly connects to a C2 (8.217.190.58) over HTTPS—IOCs and technique mapping (MITRE T1574.002) are provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.