Beagle is a previously undocumented Windows backdoor observed in 2026 in AI-themed malware campaigns and in the China-nexus intrusion cluster tracked as JadeProx. It has been delivered through DLL-sideloading infection chains that use legitimate signed Windows binaries together with malicious libraries and encrypted payload data, with intermediate execution by shellcode loaders such as DonutLoader and, in some cases, TriBack Loader. The malware has been associated with fake Claude-branded software lures distributed via sponsored search results and likely malvertising, and related activity has also shown overlap with broader espionage-oriented infrastructure and tradecraft.
Beagle is a lightweight remote-access backdoor that provides operators with command execution and file-system control on compromised hosts. Documented commands include shell execution, file upload and download, directory creation and renaming, directory listing, file deletion, and self-uninstallation. Its operators use it for post-compromise remote control and follow-on activity. Reported samples communicate with command-and-control infrastructure using encrypted messaging and have been loaded largely in memory, reducing obvious disk artifacts and complicating detection.
Observed delivery chains rely heavily on defense-evasion techniques, especially DLL sideloading and callback-based shellcode execution. In JadeProx-linked activity, TriBack Loader used Win32 callback APIs to decrypt and execute payloads while varying host binaries and execution methods across samples. In fake Claude installer campaigns, Beagle was deployed after a trojanized installer staged a signed security-product executable, a malicious DLL, and encrypted payload material, ultimately loading the backdoor in memory. Researchers noted superficial similarities to PlugX-style tradecraft, but Beagle itself has been treated as a distinct backdoor.
Victimology spans both opportunistic and targeted operations. Fake AI software campaigns appear aimed at users seeking Claude-related software, including developers and general Windows users, while JadeProx activity targeted organizations in Southeast Asia and Latin America, including government, healthcare, and education entities. Attribution to a specific threat group remains unconfirmed, but Beagle has been observed in infrastructure and intrusion patterns assessed as consistent with China-nexus activity in the JadeProx cluster.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
The campaign appears to be spreading through malvertising, where attackers pay to place malicious links in search engine ads and sponsored results.
Through this connection, an attacker can upload and download files, run commands, manage directories, and maintain persistent access on the compromised machine.
It supports a small set of commands such as running arbitrary shell commands...
While the legitimate application runs in the foreground, the VBScript quietly copies three files from the SquirrelTemp directory into the Windows Startup folder.
Both end with the user copying and running (often obfuscated) commands that ultimately result in a malware infection.
Sophos found other samples from February and April. Further investigation revealed that hackers reused the same XOR key across different Donut samples throughout the year.
used fake Claude software themes... one posing as a Venezuelan municipal tax system... signed vendor binaries that launch from user writable paths
It decrypts and runs shellcode using everyday Windows callback functions... A third path used shellcode to run Beagle
It supports a small set of commands such as ... uninstalling itself to destroy evidence.
Victims are kept in the dark, because after deploying the payload files, the VBScript writes a small batch file called ~del.vbs.bat that waits two seconds, then deletes both the original VBScript and the batch file itself.
The malicious DLL decrypts the payload hidden inside NOVupdate.exe.dat using a hardcoded XOR key and runs the result entirely in memory.
They also used anti-analysis methods, which suggests a “codebase continuity rather than a short-lived ‘smash-and-grab’ campaign.”
The operation used the newly identified TriBack Loader with DLL sideloading and Win32 callback APIs to evade detection, delivering AdaptixC2 and Beagle backdoors.
The backdoor communicates with the command-and-control (C2) server... over TCP (443) and/or UDP (8080).
46 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A previously undocumented backdoor delivered through a fake Claude site via a DLL-sideloading infection chain.
A backdoor delivered by TriBack Loader in the observed campaign.
A backdoor delivered by one TriBack infection path via shellcode, communicating with domains following the same registration pattern as the broader campaign.
Previously reported malware involved in an earlier fake Claude installer campaign, distinct from the current SectopRAT/FakeAgent activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.