logo

The Claude AI Trap: Sophos Uncovers Undocumented Backdoor Hiding in Fake “Pro” Lure

ID: 51c448c9-57d7-5388-8beb-d25ba875d4bd

STIX ID: report--51c448c9-57d7-5388-8beb-d25ba875d4bd

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-05-11

Date Updated: 2026-05-11

Author: Ddos

...
...

Sophos X-Ops identified a campaign using a fake Claude AI site (claude-pro.com) to deliver a DonutLoader stage and an apparently new backdoor via a G DATA sideloading chain; distribution infrastructure ran through Cloudflare while C2 servers were on Alibaba Cloud, and a shared XOR key among samples suggests retooling or linkage between disparate malware samples.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.