Fake OpenClaw Installer Targets Crypto Wallets and Password Managers
ID: 2d81aef1-ffd2-53bb-be18-b7a006a03654
STIX ID: report--2d81aef1-ffd2-53bb-be18-b7a006a03654
Feed Name: GBHackers
**Executive summary:** Netskope and Huntress detail a sophisticated active campaign where a fake OpenClaw installer delivers a six-module Rust infostealer named Hologram that harvests credentials from 250+ crypto wallet extensions and many password managers, using layered anti-VM checks, mouse-gating, in-memory .NET execution via clroxide, cloud/messaging services (Azure DevOps, Telegram, Hookdeck) for C2/payloads, and multiple persistence mechanisms—posing a high-risk credential-theft threat to individuals and organizations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
