Fake Claude AI Website Delivers PlugX Trojan Through Sophisticated DLL Sideloading Attack

Listen to this Post

Featured Image

🎯 Introduction: When AI Popularity Becomes a Cyber Weapon

The rapid rise of AI tools has created not only innovation but also new attack surfaces for cybercriminals. As millions of users flock to AI assistants for productivity and creativity, attackers are exploiting this trust. A recent discovery highlights how threat actors are leveraging the reputation of popular AI services to distribute advanced malware, blending social engineering with stealthy technical execution. This campaign shows how even tech-savvy users can fall victim when familiarity meets deception.

🔍 the Malware Campaign and Infection Chain

A newly uncovered cyberattack involves a fraudulent website impersonating Anthropic’s Claude AI platform, designed to trick users into downloading a malicious installer disguised as a premium version of the chatbot. According to cybersecurity researchers, the fake site closely mimics the legitimate Claude interface, making it difficult for users to distinguish between real and fake sources. Once users download the provided ZIP archive, they receive what appears to be a fully functional Claude application, reinforcing the illusion of legitimacy.

Behind the scenes, however, the installer executes a hidden malware chain linked to the PlugX remote access trojan. The attack begins with an MSI installer that contains subtle inconsistencies, such as minor spelling errors in directory names, which may go unnoticed by most users. Upon execution, the installer creates a shortcut that runs a VBScript file. This script launches the actual application interface to maintain user trust, while silently initiating malicious processes in the background.

The VBScript copies three critical files into the Windows Startup folder: a legitimate-looking executable (NOVUpdate.exe), a malicious dynamic link library (avk.dll), and an encrypted data file. The executable is a signed updater from a legitimate antivirus vendor, which helps it evade detection by appearing trustworthy. This technique, known as DLL sideloading, allows the malicious DLL to be loaded instead of the genuine one, effectively hijacking the execution process.

Once triggered, the malicious DLL decrypts the payload stored in the .dat file and executes it. This multi-stage structure is characteristic of PlugX malware, a well-known tool used in cyber espionage campaigns. Within seconds of execution, the malware establishes communication with a remote command-and-control server hosted on cloud infrastructure. It repeatedly connects over encrypted channels, enabling attackers to gain persistent remote access to the infected system.

To further evade detection, the attack includes a self-deletion mechanism. The VBScript generates a temporary batch file that deletes both itself and the script shortly after execution, leaving minimal forensic evidence behind. The only remaining traces are the sideloaded files and the active malicious process, making it significantly harder for analysts to reconstruct the attack.

Additionally, the malware modifies registry keys related to TCP/IP settings, potentially altering network behavior to maintain persistence or improve communication reliability. This combination of stealth, persistence, and deception demonstrates a highly refined attack strategy that leverages both technical sophistication and psychological manipulation.

🧩 What Undercode Say: The Real Threat Behind AI-Themed Malware Campaigns

The most dangerous element in this campaign is not the malware itself, but the timing and psychological precision behind it. Attackers are no longer relying solely on brute-force exploits or phishing emails. Instead, they are embedding their operations into cultural and technological trends. AI is currently one of the most trusted and rapidly adopted technologies, making it an ideal disguise.

This attack highlights a shift toward “trust hijacking,” where attackers borrow credibility from well-known platforms rather than building fake narratives from scratch. Users downloading a “pro version” of a popular AI tool are already primed to expect installation files, updates, and enhanced features. That expectation lowers their guard significantly.

The use of DLL sideloading is also not new, but its continued effectiveness reveals a deeper issue in endpoint security. Even signed executables from legitimate vendors can be weaponized if attackers control the environment in which they run. This creates a blind spot for many security tools that rely heavily on signature-based detection or trust models.

Another critical observation is the modular design of the malware. By separating the executable, DLL, and encrypted payload, attackers gain flexibility. They can swap out components, update payloads, or reuse the same delivery mechanism across different campaigns. This modularity also complicates detection because each component may appear benign when analyzed in isolation.

The rapid connection to a command-and-control server within seconds of execution suggests automation and preconfigured infrastructure. This is not a casual attack but part of a larger operational framework, likely designed for scalability. The use of widely accessible cloud infrastructure further obscures attribution and allows attackers to blend into normal internet traffic.

What stands out is the cleanup mechanism. Self-deleting scripts significantly reduce the attack’s footprint, making incident response more difficult. By the time a user suspects something is wrong, the initial infection vector is already gone, leaving only indirect traces. This indicates a strong understanding of forensic processes and how to evade them.

Historically, PlugX has been associated with advanced persistent threat groups, but its appearance in broader campaigns suggests that sophisticated tools are becoming commoditized. This democratization of advanced malware means that more threat actors, regardless of skill level, can launch high-impact attacks.

Ultimately, this campaign reflects a convergence of social engineering, legitimate software abuse, and advanced persistence techniques. It underscores a harsh reality: users are no longer just defending against obvious scams, but against highly convincing digital replicas of trusted ecosystems.

🔍 Fact Checker Results

✅ The attack uses DLL sideloading with a legitimate signed executable, a known MITRE technique.
✅ PlugX malware is historically linked to espionage campaigns but is now widely reused.
❌ Attribution to a specific nation-state cannot be confirmed based solely on tools used.

📊 Prediction

🔮 AI-themed malware campaigns will increase as AI adoption grows across industries.
📉 Traditional antivirus detection rates may decline against sideloading-based attacks.
⚠️ Users will face more “legitimate-looking” threats that blur the line between real and fake software.

🕵️‍📝✔️Let’s dive deep and fact‑check.

References:

Reported By: securityaffairs.com
Extra Source Hub (Possible Sources for article):
https://www.twitter.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2
Bing

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon