Mark RadarMARK RADAR
EN

Attackers Impersonate Anthropic's Claude Website to Spread PlugX Remote-Access Trojan

1 reports · First detected 2026-04-14 · Last active 2026-04-14

Anthropic's Claude is a generative AI service widely used by businesses and individuals, prompting attackers to create fake Claude Pro websites and download pages that trick users into installing malware. PlugX is a remote-access trojan that often evades detection through DLL side-loading, posing a threat to accounts, business data and corporate network security.

A cybersecurity company recently found that Claude Pro installers offered by the fake websites use DLL side-loading to deploy PlugX. Once a device is infected, hackers can remotely capture screenshots, log keystrokes and monitor the device. Researchers have published the associated indicators of compromise to help users and companies detect infections. Current reports do not disclose when the campaign was discovered, the number of victims or the amount of financial losses.

All Coverage

1 original reports

The Backstory

The history behind this event
Hackers Use Fake Claude Code Installation Page to Spread InstallFix Infostealer2026-06-08 · 3 reports · similarity 0.81

Claude Code is an Anthropic development tool that helps users write and modify code from a terminal. Because development environments often contain source code, API keys, cloud credentials and cryptocurrency wallet data, a successful attack using a fake installation page could also compromise corporate systems and supply-chain security.

The InstallFix attack disclosed on March 9 mimicked a Claude Code installation page and tricked users into copying and running a curl-to-bash command, circumventing the caution typically associated with downloads. The malware then installed Amatera Stealer to collect browser passwords, session tokens and development-environment credentials. No financial losses were publicly reported.

Hackers Spread Beagle Malware Through Fake Claude Website2026-05-08 · 1 reports · similarity 0.80

As generative AI services gain popularity, well-known brands such as Claude have become targets for impersonation in social-engineering attacks. Cybersecurity company Sophos said attackers cloned Anthropic’s Claude website and exploited users’ trust in AI tools to induce them to download software. No transaction value was involved, but victims’ computers could be remotely controlled.

Sophos recently found that hackers primarily used malicious advertising and SEO poisoning to direct search users to the fake Claude website, where they distributed a backdoor called Beagle. Once installed, Beagle can receive and execute attackers’ commands. As of July 20, 2026, available information had not disclosed when the campaign was first discovered, the number of victims or the amount of losses.

Mark Radar|MARK RADAR
All times are in Taipei time (GMT+8)