logo

Fake OpenClaw Installer Targets Password Managers and Crypto Wallets

ID: 904a5161-c46e-5faa-8ab2-5d9388817a87

STIX ID: report--904a5161-c46e-5faa-8ab2-5d9388817a87

Feed Name: Cyber Press

Threat Score
78/100

Date Published: 2026-05-08

Date Updated: 2026-05-22

Author: Varshini

...
...

This report describes a sophisticated, financially motivated credential-stealing campaign that uses a typosquatted OpenClaw installer to deliver a padded Rust dropper (Hologram) and a six-part in-memory framework (Stealth Packer). Operators employ advanced evasion and persistence techniques, abuse trusted services (Azure DevOps, a compromised law-firm domain) and Telegram dead-drops for C2, and the report includes SHA256 indicators for detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.