Malware-laced OpenClaw installers get Bing AI search boost
ID: 4fc20aea-f8b3-5ba5-a91a-8120ea033bbb
STIX ID: report--4fc20aea-f8b3-5ba5-a91a-8120ea033bbb
Feed Name: The Register (Security)
Threat Score
Threat actors published fake OpenClaw installers on GitHub that were promoted via Bing AI search results; executing the installer dropped multiple malicious components (Vidar stealer, GhostSocks proxy, Rust loaders) using a custom packer and in-memory execution techniques, enabling credential theft and turning compromised hosts into residential proxies—GitHub removed the repositories after Huntress reported them and researchers provided IOCs and behavioral details.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
