logo

Fake Claude AI website delivers new 'Beagle' Windows malware

ID: 6c3e72d2-974b-5812-8119-5aff2470982c

STIX ID: report--6c3e72d2-974b-5812-8119-5aff2470982c

Feed Name: Bleeping Computer

Threat Score
72/100

Date Published: 2026-05-07

Date Updated: 2026-05-07

Author: Bill Toulas

...
...

A Sophos analysis describes a malicious fake “Claude-Pro” website distributing a trojanized installer that uses a signed G Data updater and DonutLoader to deploy a new in-memory backdoor called Beagle. The backdoor supports basic remote-file and command execution, communicates with C2 at license.claude-pro.com (IP 8.217.190.58) over TCP/443 and UDP/8080 using AES-protected traffic, and has been seen in multiple infection chains and VirusTotal submissions; presence of NOVupdate files is a strong IOC.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.