Fake Claude AI Website Delivers New Beagle Windows Backdoor via Malvertising
ID: af83bf95-4471-516b-9247-cbd64f4bc56f
STIX ID: report--af83bf95-4471-516b-9247-cbd64f4bc56f
Feed Name: Security Boulevard
Sophos X‑Ops and Malwarebytes documented a malvertising campaign using a fake claude-pro.com site to deliver a previously undocumented Windows backdoor called Beagle. The installer (Claude-Pro-windows-x64.zip → MSI) drops NOVupdate.exe (signed G Data updater), a malicious avk.dll and an encrypted data file, abusing DLL sideloading to run an in-memory loader that retrieves Beagle; C2 is license.claude-pro.com (TCP 443 / UDP 8080) with AES-encrypted traffic. Operators have been active since at least Feb–Apr 2026 and rotated infrastructure and email providers to evade blocklists; recommended actions include blocking the domains, hunting for NOVupdate.exe/avk.dll in Startup folders, and enforcing trusted download policies.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
