Fake Claude Site Drops PlugX via Signed Antivirus Sideloading
Claude racks up 290 million monthly visits, prime bait for scammers. One fake site slips in PlugX malware through a clever DLL sideloading trick that antivirus might miss.
theAIcatchupApr 10, 20263 min read
⚡ Key Takeaways
Fake Claude site uses signed G Data binary for DLL sideloading to deploy PlugX RAT undetected.𝕏
Execution chain: VBS dropper self-deletes, phones home in 22 seconds via Alibaba IP.𝕏
AI desktop apps like Claude invite installer-based attacks; expect more as traffic surges.𝕏
The 60-Second TL;DR
Fake Claude site uses signed G Data binary for DLL sideloading to deploy PlugX RAT undetected.
Execution chain: VBS dropper self-deletes, phones home in 22 seconds via Alibaba IP.
AI desktop apps like Claude invite installer-based attacks; expect more as traffic surges.