logo

Fake Claude AI Website Delivers New Beagle Windows Backdoor via Malvertising

ID: af83bf95-4471-516b-9247-cbd64f4bc56f

STIX ID: report--af83bf95-4471-516b-9247-cbd64f4bc56f

Feed Name: Security Boulevard

Threat Score
75/100

Date Published: 2026-05-10

Date Updated: 2026-05-11

Author: Evan Rowe

...
...

Sophos X‑Ops and Malwarebytes documented a malvertising campaign using a fake claude-pro.com site to deliver a previously undocumented Windows backdoor called Beagle. The installer (Claude-Pro-windows-x64.zip → MSI) drops NOVupdate.exe (signed G Data updater), a malicious avk.dll and an encrypted data file, abusing DLL sideloading to run an in-memory loader that retrieves Beagle; C2 is license.claude-pro.com (TCP 443 / UDP 8080) with AES-encrypted traffic. Operators have been active since at least Feb–Apr 2026 and rotated infrastructure and email providers to evade blocklists; recommended actions include blocking the domains, hunting for NOVupdate.exe/avk.dll in Startup folders, and enforcing trusted download policies.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.