A new cybercrime campaign is exploiting the popularity of Claude AI, creating a fake website that mimics the official service and distributes malware for Windows. According to cybersecurity firm Sophos, the fake website promotes a supposed “Claude-Pro Relay” application, which actually installs a new backdoor called Beagle, while also triggering a complex malware chain.

The campaign was initially detected by Malwarebytes, while Sophos conducted a deeper analysis, revealing a multi-layered attack that combines social engineering, trojanized installers, and known evasion techniques. The fake website uses a domain that closely resembles the name of the service, creating the illusion of a legitimate platform for developers and users of AI tools.
Fake download that hides multiple stages of attack
Users who visit “claude-pro[.]com” and are convinced to download the approximately 505MB file named “Claude-Pro-windows-x64.zip”. The file contains an MSI installer that is presented as the Claude-Pro Relay tool.
See also: Claude AI used to attack water systems
In fact, the installation results in the creation of three files in the Windows Startup folder: NOVupdate.exe, NOVupdate.exe.dat , and avk.dll. These files are the core of the attack, allowing the malware to persist on the system and load additional malicious functions.
Multi-layer malware chain and PlugX infrastructure
Sophos revealed that the initial payload is based on DonutLoader, an open-source in-memory injector that has been used in previous cyberattacks. DonutLoader activates a backdoor that researchers call Beagle, which provides the attacker with basic remote administration capabilities.

Beagle includes functions such as executing commands, uploading and downloading files, creating folders, renaming files, and managing directories. While its feature set is not considered particularly advanced, its integration into a multi-layered attack chain makes it particularly dangerous.
In a next stage, the system utilizes PlugX-like malware execution, aiming to avoid detection and execute code in memory without a disk footprint.
Abuse of signed files and DLL sideloading
One of the most worrying elements of the attack is the use of a signed executable file from security firm G Data, which is used for DLL sideloading. The NOVupdate.exe loads the malicious avk.dll along with the encrypted payload in NOVupdate.exe.dat.
See also: Serious vulnerabilities in Salesforce Marketing Cloud
This technique allows attackers to bypass security mechanisms, as the original executable appears legitimate. The DLL takes over the decryption and execution of DonutLoader in memory, making it difficult to detect by traditional antivirus tools.
Command-and-Control infrastructure and communication
The final Beagle backdoor communicates with a command-and-control server in the domain license[.]claude-pro[.]com, using TCP over port 443 or UDP over port 8080. The communication is protected with a hardcoded AES key, which encrypts the data exchanges.
The C2 infrastructure is hosted on an IP assigned to an Alibaba Cloud, which suggests the use of commercial cloud infrastructure to hide the attackers' true location.
Multiple campaigns and alternative infection vectors
Sophos' analysis uncovered additional Beagle samples that had been uploaded to VirusTotal in previous months. These samples used different infection methods, including malicious Microsoft Defender binaries, shellcode from AdaptixC2, and fake PDF files.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
At the same time, campaigns were identified that imitated updates from well-known cybersecurity companies such as CrowdStrike, SentinelOne and Trellix, enhancing the credibility of brand impersonation attacks.

Unidentified perpetrator but familiar techniques
While Sophos has not definitively attributed the campaign to a specific threat actor, researchers point to similarities with previous operations related to the ecosystem PlugX malware, which leaves open the possibility that known groups are evolving with new tools and techniques.
See also: vm2 Node.js: 12 critical vulnerabilities allow sandbox escape
Warnings and protective measures
Experts emphasize that users should download Claude exclusively from the official website and avoid sponsored search results or unknown downloads. The presence of files with names like NOVupdate.exe on a system is a strong indicator of a breach and requires immediate investigation.
The incident highlights once again how the popularity of artificial intelligence tools is creating new scope for exploitation for cybercriminals, who combine social engineering and advanced malware techniques to bypass even mature security systems.
Source: www.bleepingcomputer.com
