logo

Fake Claude AI Site Drops Beagle Backdoor on Windows Users

ID: 395b9b9b-1f19-576b-b2e1-963d131c578b

STIX ID: report--395b9b9b-1f19-576b-b2e1-963d131c578b

Feed Name: Infosecurity Magazine (News)

Threat Score
70/100

Date Published: 2026-05-07

Date Updated: 2026-05-07

...
...

A fraudulent imitation of Anthropic's Claude website was used in a malvertising campaign to distribute a previously undocumented backdoor named Beagle. The delivered MSI drops a signed G DATA updater (NOVupdate.exe), an encrypted data blob and a malicious avk.dll which is sideloaded; the DLL decrypts the blob, runs shellcode that loads DonutLoader, and deploys the Beagle backdoor communicating with license.claude-pro.com. Researchers found related samples on VirusTotal, reused XOR keys, and hosting split across Cloudflare and Alibaba Cloud, indicating an active, persistent campaign.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.