Donuts and Beagles: Fake Claude site spreads backdoor
ID: 768e1af9-adf5-59d2-9203-27c51d325985
STIX ID: report--768e1af9-adf5-59d2-9203-27c51d325985
Feed Name: Sophos Blogs
Sophos X-Ops describes a malvertising campaign that impersonates a legitimate AI site (claude-pro.com) to distribute an MSI (Claude.msi) which drops NOVupdate.exe, NOVupdate.exe.dat and avk.dll; the chain uses DLL sideloading to run Donut shellcode which loads a newly identified backdoor called 'Beagle' that communicates with license.claude-pro.com (8.217.190.58) over AES-encrypted TCP/UDP. The report includes protocol and key details, multiple related samples reusing an XOR key, IOCs (domains, IPs, filenames), and mitigation advice and detection names.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
