Hackers Deploy Fake Claude Site to Spread Backdoor Malware
Security researchers at Sophos have identified a sophisticated cyberattack campaign targeting users of the popular AI tool, Claude. Threat actors created a fraudulent website, claude-pro[.]com, designed to mimic the official Claude interface to deceive users into downloading malicious software. The fake site features non-functional links except for the download button, which delivers poisoned installers. These installers utilize DLL sideloading techniques to deploy DonutLoader and the Beagle backdoor, a Remote Access Trojan (RAT) that grants attackers unauthorized control over infected systems. This operation highlights how cybercriminals are rapidly adapting to the widespread public interest in generative AI tools, exploiting user enthusiasm for new technology to bypass security awareness. The attack vector likely involves malicious advertising and search engine optimization (SEO) poisoning to drive traffic to the spoofed domain. Experts warn that this campaign may be linked to operators associated with the PlugX malware family. Users are strongly urged to verify URLs carefully before downloading any AI-related software and to rely only on official sources like claude.ai to avoid compromising their devices with persistent backdoor malware.
Wire timeline
Hackers Deploy Fake Claude Site to Spread Backdoor Malware
Security researchers at Sophos have identified a sophisticated cyberattack campaign targeting users of the popular AI tool, Claude. Threat actors created a fraudulent website, claude-pro[.]com, designed to mimic the official Claude interface to deceive users into downloading malicious software. The fake site features non-functional links except for the download button, which delivers poisoned installers. These installers utilize DLL sideloading techniques to deploy DonutLoader and the Beagle backdoor, a Remote Access Trojan (RAT) that grants attackers unauthorized control over infected systems. This operation highlights how cybercriminals are rapidly adapting to the widespread public interest in generative AI tools, exploiting user enthusiasm for new technology to bypass security awareness. The attack vector likely involves malicious advertising and search engine optimization (SEO) poisoning to drive traffic to the spoofed domain. Experts warn that this campaign may be linked to operators associated with the PlugX malware family. Users are strongly urged to verify URLs carefully before downloading any AI-related software and to rely only on official sources like claude.ai to avoid compromising their devices with persistent backdoor malware.
Latest from TechRadar