logo

오픈클로 사칭 피싱 확산…깃허브 개발자 노린 가짜 ‘CLAW’ 토큰 공격

ID: 4f6a1afc-d0a1-5db4-abc6-48cd15a58eec

STIX ID: report--4f6a1afc-d0a1-5db4-abc6-48cd15a58eec

Feed Name: CIO Security

Threat Score
70/100

Date Published: 2026-03-27

Date Updated: 2026-04-20

...
...

Researchers observed a crypto-focused phishing/malware campaign using the C2 domain watery-compost.today and a phishing page token-claw.xyz that targets multiple wallets (WalletConnect, MetaMask, Trust Wallet, OKX, Bybit). The malware collects wallet addresses, transaction details and user names, includes a 'nuke' capability to erase local storage and hinder forensics, and an attacker wallet address (0x6981E9EA7023a8407E4B08ad97f186A5CBDaFCf5) was extracted; users are advised to block the domains, avoid connecting wallets to untrusted sites, review recent wallet connections, and revoke approvals.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.