Cybertech Europe 2026-IT Industry Official Media Partner
Subscribe

Stay up to date with the most important news

By pressing the Subscribe button, you confirm that you have read and agree to our privacy policy and terms of use
Contact us

Sophos uncovers fake Claude AI campaign spreading advanced malware

Claude – Sophos uncovers fake Claude AI campaign spreading advanced malware | IT Industry Claude – Sophos uncovers fake Claude AI campaign spreading advanced malware | IT Industry
Sophos uncovers fake Claude AI campaign spreading advanced malware – Published by IT-Branschen

Cybersecurity researcher at Sophos X-Ops has identified a sophisticated campaign in which threat actors are exploiting the growing interest in artificial intelligence to distribute malware. The operation is based on a fraudulent website that convincingly imitates the official interface of Claude, the AI assistant developed by Anthropic.

To drive traffic to the website, the attackers used search engine optimization (SEO) and malicious search ads. By manipulating search results, they were able to direct users searching for legitimate AI tools to the fake domain.

This method allows threat actors to target people who are actively searching for AI-related tools and downloads, increasing the likelihood of a successful infection.

  • VORTIQ-X AI Governance helps companies transform AI into controllable and verifiable business value.
    VORTIQ-X is an AI Governance platform that helps organizations govern, verify, and create measurable business value from AI. The platform focuses on transparency, compliance, AI governance, and the effective use of AI in mission-critical processes.
    ADVERTISEMENT

  • The IT industry Nordic technology media platform covering cybersecurity, cloud, AI, digital transformation, channel, MSP and enterprise IT news
    The IT industry is a leading Nordic technology media platform covering cybersecurity news, artificial intelligence, cloud computing, enterprise IT, digital transformation, managed services, channel partners, software development, telecommunications, data centers, IT infrastructure, technology leadership, business innovation, and emerging technologies. Through executive interviews, industry analysis, event coverage, thought leadership, product launches, vendor updates, and market insights, the IT industry connects technology decision-makers, CIOs, CISOs, CTOs, IT managers, MSPs, resellers, distributors, technology vendors, startups, and enterprise organizations across Sweden, Norway, Denmark, Finland, and Europe. Coverage includes cybersecurity trends, AI adoption, cloud strategy, enterprise software, networking, digital infrastructure, sustainability, compliance, governance, risk management, automation, data analytics, and future technology developments.
    OWN CONTENT

  • Cybertech Europe 2026 cybersecurity conference in Rome with the IT industry as Official Media Partner
    Cybertech Europe 2026 is one of Europe's leading cybersecurity conferences, bringing together cybersecurity leaders, government officials, technology innovators, startups, investors, and enterprise decision-makers in Rome. The IT industry serves as an Official Media Partner, providing event coverage, executive interviews, industry insights, and cybersecurity news for Nordic and European audiences.
    ADVERTISEMENT

  • Maciek Szczesniak featured on IT-Branschen Wire Channel Magic Chats podcast banner
    Maciek Szczesniak appears on IT-Branschen Wire Channel Magic Chats, discussing leadership, innovation, digital transformation, and business services.
    SPONSORED

Rework of well-known attack chains

Initial analysis of the campaign indicated that it followed a well-known PlugX attack chain, a method often used by various threat actors. However, Sophos researchers discovered that while the techniques looked familiar, the payload was actually a previously unknown backdoor.

This suggests that threat actors are actively evolving established attack methods to deliver new and more difficult-to-detect malware, instead of relying on older and static strategies.

The technical execution of the attack is particularly noteworthy because legitimate software is used to bypass security solutions.

The infection chain involves a trusted and digitally signed antivirus component that is abused through a technique called DLL sideloading. This allows the malicious code to run under the guise of a legitimate process, making it difficult to detect and block by traditional security products.

Memory-based loaders and advanced malware

The campaign uses a memory-based Donut charger to execute its malicious instructions. Donut is a position-independent framework that enables execution of VBScript, JScript, and .NET assemblies directly in system memory.

By avoiding writing files to the hard drive, attackers reduce their digital footprint and can bypass many Endpoint Detection and Response (EDR) systems that primarily monitor file creation and modification.

Extensive network of fake domains

The investigation shows that the fake Claude website is not an isolated incident. Sophos researchers identified a larger network of suspicious infrastructure and multiple copycat domains. Some of the websites also pretended to represent well-known security vendors, suggesting that the operation is part of a larger and more organized cybercriminal ecosystem.

donuts-and-beagles-fake-claude-site-spreads-backdoor-01.png

The broader network demonstrates a high level of planning and resource allocation. By impersonating security companies and well-known technology vendors, attackers seek to instill trust and appear legitimate even to more cautious users.

The researchers note that this type of multifaceted method shows how quickly emerging technology trends can be exploited by organized cybercrime groups.

Sophos Head of Threat Research, Gabor Szappanos, comments:

”This yet-to-be-attributed campaign, using a fake Claude site as a cover for a malicious advertising campaign, is the latest in a series of attacks in which threat actors are exploiting popular AI brands to distribute malware and backdoors.”

He continues:

”What really stands out is the extensive effort to evade detection. The threat actors reused established techniques like DLL sideloading while also changing the payload to bypass traditional security tools.”

”In this case, a signed antivirus update from G DATA was abused to sideload a malicious DLL file that decrypted and executed Donut shellcode before deploying a previously unknown backdoor, which we have dubbed ’Beagle’.”

The researchers also noted that the same XOR key has been reused in several Donut-related examples earlier this year, suggesting that this is a long-term development of the actors' TTPs (Tactics, Techniques and Procedures).

At the same time, the malware distribution and the command and control infrastructure were under the same domain, but were deliberately hosted on different cloud providers to make shutdown and tracking more difficult.

donuts-and-beagles-fake-claude-site-spreads-backdoor-04.png

AI hijacking expected to increase

As AI tools become more common, both in private and professional life, researchers expect this type of ”AI hijacking” to increase.

Instead of focusing solely on anomalous application behaviors, such as legitimate security tools loading unexpected DLL files, recommends Sophos that organizations implement stricter policies where software may only be downloaded from official and verified sources.

Recommendations for organizations

The research underscores the importance of verifying the source of all software downloads. Organizations and individuals are advised to be very cautious with AI-related tools or applications distributed outside of official marketplaces or developers' own websites.

Security teams should also focus on monitoring system memory anomalies and reviewing DLL sideloading attempts, even when legitimate and signed executables are used.

As attackers continue to evolve their delivery methods, high digital awareness and clear software procurement policies remain some of the most effective protections against these types of social engineering-based attacks.

Stay up to date with the most important news

By pressing the Subscribe button, you confirm that you have read and agree to our privacy policy and terms of use
  • The IT industry Nordic technology media platform covering cybersecurity, cloud, AI, digital transformation, channel, MSP and enterprise IT news
    The IT industry is a leading Nordic technology media platform covering cybersecurity news, artificial intelligence, cloud computing, enterprise IT, digital transformation, managed services, channel partners, software development, telecommunications, data centers, IT infrastructure, technology leadership, business innovation, and emerging technologies. Through executive interviews, industry analysis, event coverage, thought leadership, product launches, vendor updates, and market insights, the IT industry connects technology decision-makers, CIOs, CISOs, CTOs, IT managers, MSPs, resellers, distributors, technology vendors, startups, and enterprise organizations across Sweden, Norway, Denmark, Finland, and Europe. Coverage includes cybersecurity trends, AI adoption, cloud strategy, enterprise software, networking, digital infrastructure, sustainability, compliance, governance, risk management, automation, data analytics, and future technology developments.
    OWN CONTENT

  • Cybertech Europe 2026 cybersecurity conference in Rome with the IT industry as Official Media Partner
    Cybertech Europe 2026 is one of Europe's leading cybersecurity conferences, bringing together cybersecurity leaders, government officials, technology innovators, startups, investors, and enterprise decision-makers in Rome. The IT industry serves as an Official Media Partner, providing event coverage, executive interviews, industry insights, and cybersecurity news for Nordic and European audiences.
    ADVERTISEMENT

  • VORTIQ-X AI Governance helps companies transform AI into controllable and verifiable business value.
    VORTIQ-X is an AI Governance platform that helps organizations govern, verify, and create measurable business value from AI. The platform focuses on transparency, compliance, AI governance, and the effective use of AI in mission-critical processes.
    ADVERTISEMENT

  • Maciek Szczesniak featured on IT-Branschen Wire Channel Magic Chats podcast banner
    Maciek Szczesniak appears on IT-Branschen Wire Channel Magic Chats, discussing leadership, innovation, digital transformation, and business services.
    SPONSORED