Beagle is a previously undocumented Windows backdoor observed in 2026 in intrusion chains that abused AI-themed lures and DLL sideloading. It has been seen delivered by the TriBack Loader and by DonutLoader shellcode in campaigns using fake Claude-branded software distribution, including malvertising and likely SEO-poisoned search results that directed victims to counterfeit download pages. The malware chain commonly used legitimate signed Windows binaries for sideloading, then decrypted and launched the final payload in memory to reduce detection.
Beagle provides lightweight remote access functionality for post-compromise control of infected systems. Documented commands include arbitrary shell command execution, file upload and download, directory creation and renaming, directory listing, file removal, and self-uninstallation. Its operators used encrypted command-and-control communications and in-memory execution, indicating an emphasis on stealth and operational persistence.
Beagle has been associated with the JadeProx intrusion cluster, a China-nexus espionage operation that targeted organizations in Southeast Asia and Latin America, including government, healthcare, and education entities. Separate reporting also tied Beagle to fake Claude AI installer campaigns aimed at Windows users, including developers and other individuals searching for AI tooling. Researchers noted overlaps with long-standing PlugX-style tradecraft, particularly DLL sideloading patterns, but available information does not conclusively attribute Beagle to a specific named threat group.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
The campaign appears to be spreading through malvertising, where attackers pay to place malicious links in search engine ads and sponsored results.
Cybercriminals have launched a sophisticated malvertising campaign using a fake Claude‑AI website... The deceptive site, reachable through sponsored search results, mimics Anthropic’s legitimate Claude interface and lures users into downloading what appears to be a productivity‑oriented “Claude‑Pro Relay” tool but is in fact a poisoned installer.
Through this connection, an attacker can upload and download files, run commands, manage directories, and maintain persistent access on the compromised machine.
It supports a small set of commands such as running arbitrary shell commands...
While the legitimate application runs in the foreground, the VBScript quietly copies three files from the SquirrelTemp directory into the Windows Startup folder.
Sophos found other samples from February and April. Further investigation revealed that hackers reused the same XOR key across different Donut samples throughout the year.
used fake Claude software themes... one posing as a Venezuelan municipal tax system... signed vendor binaries that launch from user writable paths
It decrypts and runs shellcode using everyday Windows callback functions... A third path used shellcode to run Beagle
It supports a small set of commands such as ... uninstalling itself to destroy evidence.
Victims are kept in the dark, because after deploying the payload files, the VBScript writes a small batch file called ~del.vbs.bat that waits two seconds, then deletes both the original VBScript and the batch file itself.
The malicious DLL decrypts the payload hidden inside NOVupdate.exe.dat using a hardcoded XOR key and runs the result entirely in memory.
They also used anti-analysis methods, which suggests a “codebase continuity rather than a short-lived ‘smash-and-grab’ campaign.”
The operation used the newly identified TriBack Loader with DLL sideloading and Win32 callback APIs to evade detection, delivering AdaptixC2 and Beagle backdoors.
The backdoor communicates with the command-and-control (C2) server... over TCP (443) and/or UDP (8080).
46 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A backdoor delivered by TriBack Loader in the observed campaign.
A backdoor delivered by one TriBack infection path via shellcode, communicating with domains following the same registration pattern as the broader campaign.
Previously reported malware involved in an earlier fake Claude installer campaign, distinct from the current SectopRAT/FakeAgent activity.
A backdoor delivered by the third observed TriBack Loader variant after an intermediate DonutLoader stage. It was associated with Claude-themed phishing infrastructure and recently documented elsewhere.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.