Fake Claude AI website delivers new 'Beagle' Windows malware
Fake Claude AI website delivers new 'Beagle' Windows malware By Bill Toulas May 7, 2026 06:02 AM A fake version for the Claude AI website offers a malicious Claude-Pro Relay…
Tracked topic
Claude is an AI assistant developed by Anthropic that uses large language models to generate text and support conversational tasks.
The base64 instructions shown in the shared Claude chat download an encoded shell script from domains such as: In variant seen by Albayrak [VirusTotal]: hxxp://customroofingcontractors[.]com/curl/b42a0ed9d1ecb72e42d6034502c304845d98805481d99cea4e259359f9ab206e In variant seen by BleepingComputer [VirusTotal]: hxxps://bernasibutuwqu2[.]com/debug/loader.sh?build=a39427f9d5bfda11277f1a58c89b7c2d The 'loader.sh' (served by the second link above) is another set of Gunzip-compressed shell instructions: Base64 code retrieves first stage 'loader.sh' payload (BleepingComputer) This compressed shell
Hackers abuse Google ads, Claude.ai chats to push Mac malwareFake Claude AI website delivers new 'Beagle' Windows malware By Bill Toulas May 7, 2026 06:02 AM A fake version for the Claude AI website offers a malicious Claude-Pro Relay…
Attackers are abusing Google Ads and legitimate Claude.ai shared chats in an active malvertising campaign. Users searching for "Claude mac download" may come across sponsored search results that list…
…The attack initially targeted packages from TanStack and Mistral AI before spreading to other projects, including UiPath, Guardrails AI, and OpenSearch, through stolen CI/CD credentials and legitimate workflows. Researchers from Socket…
…Added information from Microsoft Threat Intelligence's analysis of a payload delivered via a compromised Mistral AI package. 99% of What Mythos Found Is Still Unpatched. AI chained four zero-days into…
…The AI did the work, and it hit 2,516 devices across 106 countries in parallel , taking just minutes per target. Zero days weren't required. Known CVEs and misconfigurations were enough…
…Hackers used AI to develop zero-day exploit for web admin tool Disgruntled researcher leaks “BlueHammer” Windows zero-day exploit Recently leaked Windows zero-days now exploited in attacks New Linux 'Dirty…
…New GoGra malware for Linux uses Microsoft Graph API for comms New PCPJack worm steals credentials, cleans TeamPCP infections Australia warns of ClickFix attacks pushing Vidar Stealer malware Fake Claude AI website…