Fake Claude Campaign Uses PlugX-Style DLL Sideloading Chain
ID: 36484aa3-7bbd-5bd0-ac58-8631b86f2db0
STIX ID: report--36484aa3-7bbd-5bd0-ac58-8631b86f2db0
Feed Name: GBHackers
Researchers observed a malvertising-driven campaign using a fake Claude AI site (claude-pro.com) to distribute a trojanized installer that places NOVupdate.exe, NOVupdate.exe.dat, and a malicious avk.dll in Startup. The signed G DATA updater is sideloaded to load an encrypted payload which DonutLoader executes in memory, delivering a new backdoor dubbed Beagle that supports file operations, command execution, and C2 communications to license.claude-pro.com (8.217.190.58) over TCP 443 and UDP 8080; the report includes IOCs, encryption keys, and recommended mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
