Find notable cyber news and cases, enriched with sources, timelines, and signals.

TriBack Loader DLL sideloading delivery activity

Malware Activity
First reported
Last updated
Happening score
H score 17
1 unique sources, 1 articles

Summary

Hide ▲

TriBack Loader appeared in four DLL sideloading infection chains, expanding a Windows loader operation that delivered post-exploitation payloads and increased the risk of follow-on compromise. Two builds carried AdaptixC2, and another used DonutLoader to launch Beagle, showing that the loader was used to stage multiple payload types across separate chains. The activity also left defenders with concrete detection cues, including signed executables, malicious DLLs, and encrypted companion files in user-writable or Startup locations.

Related Happenings

Beagle backdoor distributed via fake Claude site and DLL sideloading

Malware Activity
H score23 First: 07.05.2026 16:15 Last: 07.05.2026 16:15 Sources 1

How related: A Claude-themed variant used DonutLoader to run Beagle, a backdoor Sophos was first to document.

About this happening: Beagle is being distributed through a fake Claude website and a DLL sideloading chain that drops a signed updater, malicious DLL, and encrypted payload file. The lates...

Fake Claude PlugX phishing campaign

Campaign
H score34 First: 13.04.2026 12:52 Last: 13.04.2026 12:52 Sources 1

About this happening: A February phishing campaign used a fake Claude website and fake meeting invitations to deliver PlugX malware to recipients, turning a popular AI brand into a malw...

Latest development: 07.05.2026 13:02

A fake Claude AI site at claude-pro[.]com distributed Claude-Pro-windows-x64.zip, which drops NOVupdate.exe, NOVupdate.exe.dat, and avk.dll to sideload DonutLoader and load the Beagle backdoor on Windows. The backdoor uses license[.]claude-pro[.]com for command-and-control over TCP 443 and/or UDP 8080, and related Beagle samples were submitted to VirusTotal between February and April this year.

Timeline

  1. 23.07.2026 15:20 1 articles · 3h ago

    Claude-themed MSI installer plants a Windows Startup sideloading chain

    Exploitation Observed

    A Claude-themed campaign from claude-pro[.]com, registered on March 28, 2026, served a malicious MSI installer that, after a UAC prompt, placed the sideloading chain in the Windows Startup folder for persistence.

    Show sources
  2. 23.07.2026 15:20 2 articles · 3h ago

    TriBack Loader appears in four DLL sideloading infection chains

    Technical Analysis Update

    Group-IB's July 23, 2026 analysis says TriBack Loader appears in four infection chains built around DLL sideloading, with two variants delivering AdaptixC2, a Claude-themed variant using DonutLoader to run Beagle, and a fourth variant whose payload was not recovered.

    Show sources