logo

Weaponized VS Code Extension “ClawdBot Agent” Spreads ScreenConnect RAT

ID: b32ba48a-53b8-5fbb-a16a-af10cf1caa31

STIX ID: report--b32ba48a-53b8-5fbb-a16a-af10cf1caa31

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-01-29

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

A malicious VS Code extension impersonating an AI coding assistant ("ClawdBot Agent") was published to the Marketplace and automatically activates at startup to fetch a config that installs a legitimate ConnectWise ScreenConnect client configured to connect to attacker-controlled relays. The operation uses multiple resilient delivery and persistence methods (DLL sideloading via a trojanized DWrite.dll, Dropbox-hosted MSI, hardcoded HTTP fallbacks, and PowerShell scripts), hardcoded C2/relay domains (e.g., clawdbot.getintwopc.site, meeting.bulletmailer.net, darkgptprivate.com), and ties victims to the attacker via embedded keys; the report includes IOCs, install paths (C:\Program Files (x86)\ScreenConnect Client (...)), and remediation guidance including extension removal, uninstalling ScreenConnect, blocking domains/ports, and rotating API keys.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.