Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

Comment on Sophos: Cybercriminals use fake Claude site to infect Windows PCs by Sophos finds uncensored AI service on cybercrime forum | Back End News

Дата публикации: 29-09-2026 02:30:22

[…] Sophos: Cybercriminals use fake Claude site to infect Windows PCs […]

Основное содержимое страницы с новостью.

Sophos X-Ops has uncovered a fake Claude artificial intelligence (AI) website that tricks users into downloading malware, highlighting how cybercriminals are increasingly exploiting the popularity of AI tools to target unsuspecting users.

In a blog post published May 7, Sophos said researchers investigating a fake Claude website discovered not only a malware delivery system but also a previously undocumented backdoor that gives attackers remote access to infected computers.

The malicious website, identified as claude-pro[.]com, closely resembles the legitimate Claude AI site. Visitors are encouraged to download a supposed product called “Claude-Pro Relay,” which arrives as a large compressed file containing malware disguised as a legitimate installer.

Once installed, the malware silently places files on a Windows computer and uses a technique known as DLL sideloading to hide its activity behind trusted software. Sophos said this method has long been associated with malware families such as PlugX, which has been linked to cyberespionage campaigns.

However, researchers found that the final malware delivered by the fake site was not PlugX. Instead, it was a previously unreported backdoor that Sophos named Beagle.

The Beagle malware allows attackers to remotely control infected devices. According to Sophos, operators can execute commands, upload and download files, create directories, rename files, and remove data from a victim’s computer.

“We were unable to find any public reporting about this backdoor and have dubbed it ‘Beagle,'” Sophos researchers wrote in the report.

The malware communicates with command-and-control servers over internet connections commonly used for normal web traffic, making detection more difficult. Sophos also identified several related malware samples dating back to February 2026, suggesting the campaign may have been active for months and continues to evolve.

Researchers said the attack illustrates how threat actors are adapting their tactics to capitalize on growing public interest in AI platforms. Rather than relying on sophisticated technical exploits, attackers are using fake websites, sponsored search results, and search engine manipulation to lure victims into installing malware themselves.

For users in the Philippines, where AI tools such as Claude, ChatGPT, and Gemini continue to gain popularity among students, professionals, and businesses, the campaign serves as a reminder to download software only from official websites and verify web addresses before installing applications.

Sophos said the fake Claude website was relatively simple compared with other impersonation campaigns, but its effectiveness lies in exploiting user trust in well-known AI brands.

The company also noted similarities between this campaign and previous malware operations, although it said additional evidence is needed before linking the attacks to a specific threat actor.

Post navigation

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1Sophos finds uncensored AI service advertised on cybercrime forum07.8426-09-2026
2 Comment on Globe Business, Cyble partner to strengthen enterprise cybersecurity with AI by Cyble: Ransomware attacks reach 2026 high in August | Back End News 01029-09-2026
3 Comment on Alibaba Cloud boosts AI ecosystem with agent services by Alibaba Cloud expands global network for business AI | Back End News 07.8102-10-2026
4 Comment on Synology expands AI-powered data protection portfolio by Data security hinders Philippine AI adoption, Synology finds | Back End News 014.301-10-2026
5 Comment on VSTECS brings Fastly edge security platform to PH by Fastly: AI traffic raises new demands on business websites | Back End News 08.4829-09-2026
6 Comment on AMD expands AI systems for businesses and data centers by AMD’s new processors allow businesses to run AI agents locally | Back End News 08.1501-10-2026
7 Comment on AWS opens 2025 GenAI Accelerator applications for startups by AWS offers cloud training rewards to Philippine students | Back End News 013.3204-10-2026
8 Comment on Kaspersky finds 250,000 GitHub Actions security issues by Kaspersky finds torrent malware infecting users and businesses | Back End News 013.3301-10-2026
9Defending against AI-fueled social engineering012.0701-09-2026
10The SOC Doesn't Need to Start Over with Every Alert08.6525-09-2026

Классификация: Мнения. Схожих патентов: 0. Схожих новостей: 10. Тональность: 0. Информативность: 7.63. Источник: backendnews.net.