logo

OpenClaw Trap: AI-Assisted Lure Factory Targets Developers & Gamers

ID: 10f8ef29-55f5-5a28-bb85-80fed27143f4

STIX ID: report--10f8ef29-55f5-5a28-bb85-80fed27143f4

Feed Name: Netskope Threat Labs

Threat Score
78/100

Date Published: 2026-03-24

Date Updated: 2026-04-28

Author: Vini Egerland

...
...

Netskope Threat Labs discovered and analyzed a large-scale malware campaign (“TroyDen’s Lure Factory”) that trojanizes GitHub repositories (developer tools, game cheats, phone trackers, etc.) to deliver a Prometheus-obfuscated LuaJIT loader. The two-component payload (renamed Lua runtime + encrypted Lua script) evades automated sandboxes via multiple anti-analysis checks and an extreme Sleep, then disables proxy detection, geolocates the host, captures full-desktop screenshots and posts them to C2 servers in Frankfurt which return encrypted task/loader blobs; more than 300 delivery packages and multiple C2 nodes were observed and Netskope provided IOCs for detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.