216.73.217.22

Donuts and Beagles: Fake Claude site spreads backdoor

· Published 07/05/2026 17:05 · Modified 08/05/2026 09:21

Export JSON

Essential information

Published
07/05/2026 17:05
Modified
08/05/2026 09:21
Tags
2026-05-07 adaptixc2 beagle beagle backdoor donutloader
Related entities
15 techniques (mitre), 5 malware, 2 others

Description

A fraudulent website impersonating Anthropic's Claude AI platform has been distributing a previously undocumented backdoor called through malvertising campaigns. The attack begins when victims download a fictitious tool named Claude-Pro Relay from claude-pro[.]com, delivered as a 505 MB ZIP archive. The infection chain utilizes DLL sideloading, exploiting a signed G DATA antivirus updater to load malicious code. The technique mirrors PlugX delivery methods but deploys different payloads. supports eight commands including shell execution, file transfer, and directory listing, communicating with C2 servers using AES encryption. Related samples dating to February 2026 have been identified, with some variants delivering framework. Additional domains impersonated security vendors like Trellix, CrowdStrike, and SentinelOne. The infrastructure spans Cloudflare for distribution and Alibaba Cloud for command and control.

External references