The Claude AI Trap: Sophos Uncovers Undocumented Backdoor Hiding in Fake “Pro” Lure
ID: 51c448c9-57d7-5388-8beb-d25ba875d4bd
STIX ID: report--51c448c9-57d7-5388-8beb-d25ba875d4bd
Feed Name: securityonline.info
Threat Score
Sophos X-Ops identified a campaign using a fake Claude AI site (claude-pro.com) to deliver a DonutLoader stage and an apparently new backdoor via a G DATA sideloading chain; distribution infrastructure ran through Cloudflare while C2 servers were on Alibaba Cloud, and a shared XOR key among samples suggests retooling or linkage between disparate malware samples.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
