Security researchers at Sophos report that a fraudulent website impersonating Anthropic’s Claude AI is used to distribute malware to Windows users. Victims who visit the fake Claude site are directed to a malicious download chain that results in the installation of DonutLoader and a new Beagle backdoor. According to the reports, the infection process relies on DLL sideloading, where a malicious or crafted dynamic-link library is placed or loaded in a way that causes a legitimate application component to execute attacker-controlled code.
Both sources describe the campaign as an imitation of Claude and emphasize the role of DLL sideloading in delivering the payload. The malware components referenced include DonutLoader (a loader used to enable further malicious activity) and the Beagle backdoor (intended to provide remote access or control after compromise). The reports do not specify the exact geographic spread, volume of infections, or specific lure content beyond the use of the fake Claude site. Overall, the accounts focus on the observed technique and the malware families involved in this impersonation-driven delivery mechanism.