Fake OpenClaw Installer Targets Password Managers and Crypto Wallets
ID: 904a5161-c46e-5faa-8ab2-5d9388817a87
STIX ID: report--904a5161-c46e-5faa-8ab2-5d9388817a87
Feed Name: Cyber Press
Threat Score
This report describes a sophisticated, financially motivated credential-stealing campaign that uses a typosquatted OpenClaw installer to deliver a padded Rust dropper (Hologram) and a six-part in-memory framework (Stealth Packer). Operators employ advanced evasion and persistence techniques, abuse trusted services (Azure DevOps, a compromised law-firm domain) and Telegram dead-drops for C2, and the report includes SHA256 indicators for detection and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
