Fake Claude AI Installer Targets Windows Users with PlugX Malware
ID: bf075fe5-e53f-5e77-a805-ed968174b0c2
STIX ID: report--bf075fe5-e53f-5e77-a805-ed968174b0c2
Feed Name: HackRead
Threat Score
Malwarebytes uncovered a phishing campaign distributing a fake "Claude Pro" Windows installer that sideloads a malicious avk.dll via a signed NOVUpdate.exe to install PlugX, persist in Startup, and rapidly connect to C2 at 8.217.190.58:443; researchers published IOCs (filenames, registry changes, IP/port), described the DLL sideloading and VBScript dropper TTPs, and warned users to obtain AI tools only from official sites.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
