Bing AI promoted fake OpenClaw GitHub repo pushing info-stealing malware
ID: 0550164d-7384-5838-bd10-e83c06c578e6
STIX ID: report--0550164d-7384-5838-bd10-e83c06c578e6
Feed Name: Bleeping Computer
Researchers at Huntress uncovered a campaign in which threat actors published fake OpenClaw installers on GitHub that were recommended by Bing AI search results; users who followed the installation instructions executed commands that installed Rust-based loaders which ran information stealers (Atomic Stealer, Vidar) and GhostSocks backconnect proxy malware, enabling credential theft and turning victims into proxy nodes. Several malicious repositories and files were identified and reported to GitHub, and some samples were quarantined by Windows Managed AV/Defender for Endpoint.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
