Fake Claude website distributes the PlugX backdoor
Researchers at Malwarebytes have found a fake website distributing a trojanised version of Claude carrying the PlugX backdoor. The attack itself uses familiar lures and well-known execution techniques. What stands out is the payload: PlugX has been known for well over a decade and has mainly featured in espionage campaigns tied to China-nexus threat actors. Distributing it through publicly available trojanised installers breaks that pattern. The researchers attribute the shift to PlugX source code circulating in underground forums.
What this means for your organisation
Employees download AI tools on their own initiative, usually faster than IT can form a view on them. When they search their way to an installer, there is no guarantee they land on the right site. The point is not Claude specifically, but that sought-after tools make attractive lures, and that finding PlugX in your logs no longer automatically means state-sponsored espionage. That makes severity harder to judge for whoever is handling the incident.
Berigo recommends
- Give staff a short, clear list of which AI tools are approved and where to get them.
- Restrict the ability to install software on company machines.
- Make requesting a new tool easy and low-friction, otherwise people will solve it themselves.
- Update detection rules so a PlugX hit triggers investigation regardless of which actor you expect.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch