Fake Claude site installs malware that gives attackers access to your computer
ID: 38eab331-6d54-5c0d-aa63-4b7c4dca7bf6
STIX ID: report--38eab331-6d54-5c0d-aa63-4b7c4dca7bf6
Feed Name: Malwarebytes Blog
Threat Score
A malicious campaign impersonating Anthropic’s Claude offers a trojanized installer (Claude-Pro-windows-x64.zip) that appears to run the legitimate app while deploying a PlugX RAT via a signed G DATA sideloading triad (NOVUpdate.exe, avk.dll, NOVUpdate.exe.dat). Sandbox telemetry shows rapid C2 callbacks to 8.217.190.58:443 and the dropper hides and deletes itself; the report includes file hashes, filenames, and remediation steps.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
