logo

Fake OpenClaw Installer Targets Crypto Wallets and Password Managers

ID: 2d81aef1-ffd2-53bb-be18-b7a006a03654

STIX ID: report--2d81aef1-ffd2-53bb-be18-b7a006a03654

Feed Name: GBHackers

Threat Score
80/100

Date Published: 2026-05-08

Date Updated: 2026-05-08

Author: Mayura Kathir

...
...

**Executive summary:** Netskope and Huntress detail a sophisticated active campaign where a fake OpenClaw installer delivers a six-module Rust infostealer named Hologram that harvests credentials from 250+ crypto wallet extensions and many password managers, using layered anti-VM checks, mouse-gating, in-memory .NET execution via clroxide, cloud/messaging services (Azure DevOps, Telegram, Hookdeck) for C2/payloads, and multiple persistence mechanisms—posing a high-risk credential-theft threat to individuals and organizations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.