Sophos X-Ops: Attackers Impersonate Claude, ChatGPT, Copilot and Perplexity to Distribute Infostealers, Backdoors and Malicious Browser Extensions — Threadlinqs Intelligence
As of 2026-08-23, Sophos X-Ops: Attackers Impersonate Claude, ChatGPT, Copilot and Perplexity to Distribute Infostealers, Backdoors and Malicious Browser Extensions is a high-severity malware threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 30 indicators of compromise.
Threat ID: TL-2026-2120 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Sophos X-Ops reviewed 12 months of MDR case data (July 2025-June 2026) and confirmed 38 incidents of malicious activity impersonating popular AI brands, 30 of them software impersonation and 26
Between 2 July 2025 and 29 June 2026, Sophos X-Ops reviewed 86 MDR cases tagged for AI involvement and confirmed 38 as genuinely adversarial. Of those, 35 targeted AI brands/ecosystem and 30 were direct software impersonation, with Claude the most abused lure (26 of 38 cases) ahead of ChatGPT, Microsoft Copilot, and Perplexity.
The dominant delivery technique is a ClickFix variant Sophos calls 'InstallFix': malvertising and SEO-poisoned search results steer victims to typosquatted sites that present a polished, fake step-by-step 'installation guide' ending in a copy-pasted obfuscated command. In one documented chain, a fake Claude site had victims run an mshta one-liner pulling a payload from download-version[.]1-9-18[.]com; the payload was a Windows app package named 'claude' or 'claude.msixbundle', followed by an `irm <url> | iex` one-liner that executed in memory and attempted process hollowing against the browser. Other InstallFix variants used trojanized 'Claude Setup.zip' archives staging a malicious libcef.dll, and a repackaged claude.exe acting as a loader; a related fake-CAPTCHA ClickFix flow distributed LummaStealer.
A separate, previously-undocumented backdoor named 'Beagle' was distributed from a cloned Claude site (claude-pro.com, live since ~March 2026, hosted on Alibaba Cloud behind Cloudflare) offering a fictitious 'Claude-Pro Relay' as a 505 MB ZIP. The archive's MSI installer drops a signed G DATA antivirus updater (renamed NOVupdate.exe), an encrypted data file, and a malicious avk.dll into the Windows startup folder; when the legitimate, signed updater runs it side-loads avk.dll in place of its real library, which reverses an XOR-encoded blob, runs shellcode, and launches an in-memory DonutLoader that ultimately deploys Beagle. Beagle supports eight commands (CMD/PowerShell execution, file upload/download, directory listing/creation/deletion, file rename, self-removal) and beacons to license[.]claude-pro[.]com over TCP/443 or UDP/8080 with a hardcoded AES key; a March 2026 variant instead deployed AdaptixC2. Sophos notes structural similarity to PlugX-style loader chains without formally attributing the cluster.
On the extension front, Sophos found a fake Perplexity browser extension published on the Chrome Web Store — with a 4.7-star rating across 67 reviews and 10,000+ installs — that hijacked searches, redirected traffic through perplexity-ai[.]online, displayed a Tilda-hosted landing page (extension.tilda.ws/perplexityai) post-install, and exfiltrated real-time browsing telemetry to attacker infrastructure. A second extension marketed as an 'AI Sidebar with DeepSeek, ChatGPT, Claude' functioned the same way, beaconing stolen data to its own C2.
The most novel finding is a custom Rust-based RAT discovered during a financial-services intrusion. Its source was recovered from a public GitHub repository with visible commit history showing two contributors: a human threat-actor account and a 'claude' AI coding-agent account (built on an agentic skills framework), with the config internally renamed from 'rat-agent' to 'svc' across the development history. The RAT polls a Slack channel for host-tagged operator commands and supports remote command execution, reverse shell, file download, DPAPI-encrypted configuration retrieval, and scheduled-task-based persistence; development spanned several days of iterative feature/encryption/hardening commits.
Sophos also flags — as a separate, lower-confidence finding from the same 38-incident review — a SonicWall SMA1000 ransomware intrusion (via the actively-exploited CVE-2026-15409/CVE-2026-15410 SSRF+code-injection chain) where PowerShell used for internal reconnaissance carried unusually verbose, templated, English-narrated comments and, in one script, Mandarin-language comments — a pattern consistent with, though not conclusive proof of, LLM-generated tooling; the leaked internal chats of the unrelated 'Gentlemen' ransomware group separately show the group promot
Weaknesses (CWE)
CWE-494, CWE-506
Target sectors: finance, technology, general opportunistic
Target regions: Global
Timeline
- Start of the 12-month Sophos X-Ops MDR case review window later found to contain 38 confirmed AI-brand-impersonation/malicious-AI-use incidents.
- Earliest Beagle backdoor samples identified on VirusTotal, per Sophos' campaign timeline.
- Malicious hosting infrastructure for the cloned claude-pro.com site established on Alibaba Cloud, fronted by Cloudflare.
- A March 2026 Beagle campaign variant deploys the AdaptixC2 framework as an alternate payload.
- Leaked internal chats show the unrelated 'Gentlemen' ransomware group promoting an uncensored Qwen3.5 build to affiliates (cited by Sophos as a separate 'malicious use of AI' data point from the same review).
- Sophos publishes 'Donuts and Beagles', disclosing the previously undocumented Beagle backdoor and its claude-pro.com distribution chain.
- End of the 12-month Sophos X-Ops MDR case review window.
- Sophos X-Ops publishes 'Fake AI, real malware', consolidating 38 confirmed incidents across ClickFix/InstallFix, the Beagle backdoor, the fake Perplexity extension, and the Slack-based Rust RAT.
- Help Net Security, GBHackers, Cyber Security News and others report on the Sophos findings, amplifying the disclosure.
Related threats
- Fake AI Developer Tool Installers Delivering Infostealer via SEO Poisoning and Typosquatting
- JadeProx: China-Nexus Campaign Deploys TriBack Loader Against Government, Healthcare, and Education Targets in APAC and Latin America
- Mass Phishing/Fraud Campaign Impersonating Anthropic Claude and Mythos Brands (3,188 Malicious Domains)
- Infostealer-Enabled ClickFix Campaign Compromises Artlist via EtherHiding C2 and DLL Side-Loaded RAT
- Fake Google/Cloudflare Verification Pages Spread Multiple Malware Families via ClickFix (HijackLoader, StealC, Remus Stealer, Amatera Stealer, CastleLoader, NetSupport RAT, ResiLoader)
- ACR Stealer (Amatera Stealer) Uses ClickFix Lures, WebDAV/pushd DLL Delivery, and EtherHiding to Harvest Browser and Microsoft 365 Data
Detections & IOCs
As of 2026-09-06, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 30 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
MALWARE, HIGH, threat intelligence, cybersecurity, T1583.001, T1583.008, T1608.006, T1204.004, T1204.002, T1059.001, T1218.005, T1055.012, T1027, T1574.001