Cybersecurity researcher at Sophos X-Ops has identified a sophisticated campaign in which threat actors are exploiting the growing interest in artificial intelligence to distribute malware. The operation is based on a fraudulent website that convincingly imitates the official interface of Claude, the AI assistant developed by Anthropic.
To drive traffic to the website, the attackers used search engine optimization (SEO) and malicious search ads. By manipulating search results, they were able to direct users searching for legitimate AI tools to the fake domain.
This method allows threat actors to target people who are actively searching for AI-related tools and downloads, increasing the likelihood of a successful infection.
Rework of well-known attack chains
Initial analysis of the campaign indicated that it followed a well-known PlugX attack chain, a method often used by various threat actors. However, Sophos researchers discovered that while the techniques looked familiar, the payload was actually a previously unknown backdoor.
This suggests that threat actors are actively evolving established attack methods to deliver new and more difficult-to-detect malware, instead of relying on older and static strategies.
The technical execution of the attack is particularly noteworthy because legitimate software is used to bypass security solutions.
The infection chain involves a trusted and digitally signed antivirus component that is abused through a technique called DLL sideloading. This allows the malicious code to run under the guise of a legitimate process, making it difficult to detect and block by traditional security products.
Memory-based loaders and advanced malware
The campaign uses a memory-based Donut charger to execute its malicious instructions. Donut is a position-independent framework that enables execution of VBScript, JScript, and .NET assemblies directly in system memory.
By avoiding writing files to the hard drive, attackers reduce their digital footprint and can bypass many Endpoint Detection and Response (EDR) systems that primarily monitor file creation and modification.
Extensive network of fake domains
The investigation shows that the fake Claude website is not an isolated incident. Sophos researchers identified a larger network of suspicious infrastructure and multiple copycat domains. Some of the websites also pretended to represent well-known security vendors, suggesting that the operation is part of a larger and more organized cybercriminal ecosystem.

The broader network demonstrates a high level of planning and resource allocation. By impersonating security companies and well-known technology vendors, attackers seek to instill trust and appear legitimate even to more cautious users.
The researchers note that this type of multifaceted method shows how quickly emerging technology trends can be exploited by organized cybercrime groups.
Sophos Head of Threat Research, Gabor Szappanos, comments:
”This yet-to-be-attributed campaign, using a fake Claude site as a cover for a malicious advertising campaign, is the latest in a series of attacks in which threat actors are exploiting popular AI brands to distribute malware and backdoors.”
He continues:
”What really stands out is the extensive effort to evade detection. The threat actors reused established techniques like DLL sideloading while also changing the payload to bypass traditional security tools.”
”In this case, a signed antivirus update from G DATA was abused to sideload a malicious DLL file that decrypted and executed Donut shellcode before deploying a previously unknown backdoor, which we have dubbed ’Beagle’.”
The researchers also noted that the same XOR key has been reused in several Donut-related examples earlier this year, suggesting that this is a long-term development of the actors' TTPs (Tactics, Techniques and Procedures).
At the same time, the malware distribution and the command and control infrastructure were under the same domain, but were deliberately hosted on different cloud providers to make shutdown and tracking more difficult.

AI hijacking expected to increase
As AI tools become more common, both in private and professional life, researchers expect this type of ”AI hijacking” to increase.
Instead of focusing solely on anomalous application behaviors, such as legitimate security tools loading unexpected DLL files, recommends Sophos that organizations implement stricter policies where software may only be downloaded from official and verified sources.
Recommendations for organizations
The research underscores the importance of verifying the source of all software downloads. Organizations and individuals are advised to be very cautious with AI-related tools or applications distributed outside of official marketplaces or developers' own websites.
Security teams should also focus on monitoring system memory anomalies and reviewing DLL sideloading attempts, even when legitimate and signed executables are used.
As attackers continue to evolve their delivery methods, high digital awareness and clear software procurement policies remain some of the most effective protections against these types of social engineering-based attacks.








