As cited
Copy frozen at (site build).
threat intel
Donuts and Beagles: Fake Claude site spreads backdoor
A fake website impersonating Anthropic's Claude AI platform is distributing malware through DLL sideloading attacks that establish a backdoor on infected systems. The campaign uses malvertising to direct users to the fraudulent site, where downloads are weaponized with the Beagle backdoor and DONUT malware.
Why it matters: Organizations and developers using Claude or searching for AI tools are at risk of downloading backdoored software that could compromise credentials and system access; practitioners should warn users against unofficial Claude sites and monitor for suspicious DLL sideloading activity.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Donuts and Beagles: Fake Claude site spreads backdoor
No summary had been written when this copy was frozen.
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Donuts and Beagles: Fake Claude site spreads backdoor
A fraudulent site posing as Anthropic’s Claude chat service appears in search results and advertisements. Visitors who click the link receive a payload that uses DLL sideloading to install a backdoor.
Why it matters: Anyone looking for Anthropic’s Claude service may inadvertently download a DLL sideloading backdoor, so they should verify site authenticity and avoid unsolicited downloads.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Donuts and Beagles: Fake Claude site spreads backdoor
A fraudulent site posing as Anthropic’s Claude chat service appears in search results and advertisements. Visitors who click the link receive a payload that uses DLL sideloading to install a backdoor.
Why it matters: Anyone looking for Anthropic’s Claude service may inadvertently download a DLL sideloading backdoor, so they should verify site authenticity and avoid unsolicited downloads.
- Source published
- First seen by Cybersecurity Tracker