Hackers Use Fake OpenClaw Installer to Steal Crypto Wallet and Password Manager Credentials
ID: 4c9fe5d2-fb47-5bce-adbd-b4ed302d2dc7
STIX ID: report--4c9fe5d2-fb47-5bce-adbd-b4ed302d2dc7
Feed Name: cybersecurityNews.com
A sophisticated infostealer campaign masquerades as an OpenClaw installer (OpenClaw_x64.7z) containing a large Rust executable padded to evade sandboxes; once executed it performs VM/sandbox checks, waits for real user input, disables Defender, and downloads six modular components that harvest credentials from over 250 browser extensions (including many crypto wallets and password managers), fingerprint systems, maintain layered persistence, and use rotating infrastructure (Telegram dead-drops, Hookdeck relay, Azure DevOps staging) to evade takedown; the report includes numerous file hashes, domains, IPs, mutexes, registry persistence keys, and staging URLs as IoCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
