Hackers Spread Beagle Malware Through Fake Claude Website
As generative AI services gain popularity, well-known brands such as Claude have become targets for impersonation in social-engineering attacks. Cybersecurity company Sophos said attackers cloned Anthropic’s Claude website and exploited users’ trust in AI tools to induce them to download software. No transaction value was involved, but victims’ computers could be remotely controlled.
Sophos recently found that hackers primarily used malicious advertising and SEO poisoning to direct search users to the fake Claude website, where they distributed a backdoor called Beagle. Once installed, Beagle can receive and execute attackers’ commands. As of July 20, 2026, available information had not disclosed when the campaign was first discovered, the number of victims or the amount of losses.
All Coverage
1 original reportsThe Backstory
The history behind this eventAttackers Impersonate Anthropic's Claude Website to Spread PlugX Remote-Access Trojan
Anthropic's Claude is a generative AI service widely used by businesses and individuals, prompting attackers to create fake Claude Pro websites and download pages that trick users into installing malware. PlugX is a remote-access trojan that often evades detection through DLL side-loading, posing a threat to accounts, business data and corporate network security.
A cybersecurity company recently found that Claude Pro installers offered by the fake websites use DLL side-loading to deploy PlugX. Once a device is infected, hackers can remotely capture screenshots, log keystrokes and monitor the device. Researchers have published the associated indicators of compromise to help users and companies detect infections. Current reports do not disclose when the campaign was discovered, the number of victims or the amount of financial losses.
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.