logo

Fake Claude AI Installer Targets Windows Users with PlugX Malware

ID: bf075fe5-e53f-5e77-a805-ed968174b0c2

STIX ID: report--bf075fe5-e53f-5e77-a805-ed968174b0c2

Feed Name: HackRead

Threat Score
75/100

Date Published: 2026-04-15

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

Malwarebytes uncovered a phishing campaign distributing a fake "Claude Pro" Windows installer that sideloads a malicious avk.dll via a signed NOVUpdate.exe to install PlugX, persist in Startup, and rapidly connect to C2 at 8.217.190.58:443; researchers published IOCs (filenames, registry changes, IP/port), described the DLL sideloading and VBScript dropper TTPs, and warned users to obtain AI tools only from official sites.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.