TriBack Loader DLL sideloading delivery activity
Malware Activity
Summary
Hide ▲
Show ▼
TriBack Loader appeared in four DLL sideloading infection chains, expanding a Windows loader operation that delivered post-exploitation payloads and increased the risk of follow-on compromise. Two builds carried AdaptixC2, and another used DonutLoader to launch Beagle, showing that the loader was used to stage multiple payload types across separate chains. The activity also left defenders with concrete detection cues, including signed executables, malicious DLLs, and encrypted companion files in user-writable or Startup locations.
Related Happenings
Beagle backdoor distributed via fake Claude site and DLL sideloading
Malware Activity
H score23
First: 07.05.2026 16:15
Last: 07.05.2026 16:15
Sources 1
How related:
A Claude-themed variant used DonutLoader to run Beagle, a backdoor Sophos was first to document.
About this happening:
Beagle is being distributed through a fake Claude website and a DLL sideloading chain that drops a signed updater, malicious DLL, and encrypted payload file. The lates...
Beagle backdoor distributed via fake Claude site and DLL sideloading
Malware ActivityHow related: A Claude-themed variant used DonutLoader to run Beagle, a backdoor Sophos was first to document.
About this happening: Beagle is being distributed through a fake Claude website and a DLL sideloading chain that drops a signed updater, malicious DLL, and encrypted payload file. The lates...
Fake Claude PlugX phishing campaign
Campaign
H score34
First: 13.04.2026 12:52
Last: 13.04.2026 12:52
Sources 1
About this happening:
A February phishing campaign used a fake Claude website and fake meeting invitations to deliver PlugX malware to recipients, turning a popular AI brand into a malw...
Fake Claude PlugX phishing campaign
CampaignAbout this happening: A February phishing campaign used a fake Claude website and fake meeting invitations to deliver PlugX malware to recipients, turning a popular AI brand into a malw...
Latest development: 07.05.2026 13:02
A fake Claude AI site at claude-pro[.]com distributed Claude-Pro-windows-x64.zip, which drops NOVupdate.exe, NOVupdate.exe.dat, and avk.dll to sideload DonutLoader and load the Beagle backdoor on Windows. The backdoor uses license[.]claude-pro[.]com for command-and-control over TCP 443 and/or UDP 8080, and related Beagle samples were submitted to VirusTotal between February and April this year.
Timeline
-
23.07.2026 15:20 1 articles · 3h ago
Claude-themed MSI installer plants a Windows Startup sideloading chain
Exploitation ObservedA Claude-themed campaign from claude-pro[.]com, registered on March 28, 2026, served a malicious MSI installer that, after a UAC prompt, placed the sideloading chain in the Windows Startup folder for persistence.
Show sources
- China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks — thehackernews.com — 23.07.2026 15:20
-
23.07.2026 15:20 2 articles · 3h ago
TriBack Loader appears in four DLL sideloading infection chains
Technical Analysis UpdateGroup-IB's July 23, 2026 analysis says TriBack Loader appears in four infection chains built around DLL sideloading, with two variants delivering AdaptixC2, a Claude-themed variant using DonutLoader to run Beagle, and a fourth variant whose payload was not recovered.
Show sources
- China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks — thehackernews.com — 23.07.2026 15:20
- China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks — thehackernews.com — 23.07.2026 15:20