Hackers Use Fake Claude AI Site to Infect Users With New Beagle Malware

https://hackread.com/wp-content/uploads/2026/05/fake-claude-ai-site-spreads-new-beagle-backdoor-1024x576.jpg

Hackers are using AI popularity to trick people into installing malware. According to new research from Sophos X-Ops, shared with Hackread.com, a fake website designed to look like Anthropic’s Claude AI has been discovered spreading a previously unknown backdoor.

The deception starts with a malicious domain called claude-pro.com. Using malvertising (ads showing malicious links on real websites) and SEO poisoning (manipulating search engine results to increase a site’s ranking) to reach victims. To a normal user, it looked like a legitimate platform to get AI tools. However, it was actually a trap.

How the infection happens

When a visitor clicks the download link for a supposed Claude-Pro Relay tool, they receive a file named Claude-Pro-windows-x64.zip. Inside this file is an MSI installer ‘Claude.msi,’ which drops three specific files into the computer’s startup folder: NOVupdate.exe, avk.dll, and an encrypted data file called NOVupdate.exe.dat.

What makes this entire attack unusual is that...

Copyright of this story solely belongs to hackread.com. To see the full text click HERE

Read more