Malicious OpenClaw Skills Used to Distribute Atomic macOS Stealer
ID: b51884e4-dda1-5e07-8596-f37821e1d87b
STIX ID: report--b51884e4-dda1-5e07-8596-f37821e1d87b
Feed Name: TrendAI Security Blog
TrendAI Research discovered a campaign distributing Atomic macOS Stealer (AMOS) via malicious OpenClaw agent skills that instruct AI agents or users to install a fake OpenClawCLI; the delivered Mach-O universal binary harvests credentials, keychains, browser data, crypto wallets, Telegram/Discord data and other files, compresses them, and uploads to a C2. The report includes infection-chain artifacts (Base64-encoded installer commands, C2 upload endpoints), binary analysis (multi-key XOR string encryption, master keys), detection evidence (VirusTotal detections, TrendAI blocking), recommended mitigations (use of MDR, containerized testing, hunting queries) and links to IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
