[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fPARdARPGvNlXdXXeqzeijgmxAXxlRg-MFGixVEkxTLM":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":18,"created_at":19,"published_at":20,"article":21,"tags":25,"podcasts":38},"f1dea723-7d10-4778-8814-68f9b3f8a062","fake-ai-tool-installer-delivers-plugx-malware-via-phishing-campaign","396800c1-11fb-4ff7-aa52-89fabc476cdf","Fake AI Tool Installer Delivers PlugX Malware via Phishing Campaign","Cybercriminals created a fraudulent Anthropic Claude website to distribute PlugX malware through fake AI tool installers, exploiting users' trust in popular AI applications. The attack leveraged DLL sideloading with legitimate signed binaries to bypass security controls and establish persistent remote access. This campaign demonstrates how threat actors are expanding beyond traditional software piracy targets to exploit the growing popularity of AI tools. Users downloading software from unofficial sources or responding to phishing emails risk compromising their systems with sophisticated malware.","**Immediate actions:**\n- Verify all software downloads come from official vendor websites and app stores\n- Block the identified C2 infrastructure (8.217.190.58) at network perimeter\n- Scan systems for NOVUpdate.exe and Claude-Pro-windows-x64.zip files\n\n**Long-term improvements:**\n- Implement application whitelisting to prevent unauthorized executables from running\n- Deploy email security solutions that detect and block phishing campaigns\n- Establish software procurement policies requiring downloads only from verified sources\n\n**Detection measures:**\n- Monitor for DLL sideloading activities and unsigned DLL loads by legitimate processes\n- Set up alerts for connections to suspicious IP addresses and domains\n- Enable endpoint detection to identify PlugX malware signatures and behaviors",[12,13,14,15,16,17],"CIS Control 2","CIS Control 7","CIS Control 12","NIST AC-20","NIST SI-3","NIST AT-2","published","2026-04-15T23:08:12.443705+00:00","2026-04-15T23:08:12.295+00:00",{"id":7,"url":22,"slug":23,"title":24},"https:\u002F\u002Fhackread.com\u002Ffake-claude-ai-installer-plugx-malware-windows-users\u002F","fake-claude-ai-installer-targets-windows-users-with-plugx-malware-43c538","Fake Claude AI Installer Targets Windows Users with PlugX Malware",[26,32],{"id":27,"name":28,"slug":29,"description":30,"color":31},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":33,"name":34,"slug":35,"description":36,"color":37},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[]]