logo

OpenClaw Skill Distributes Remcos & GhostLoader

ID: a3b604a5-659a-562e-83ca-dca0f3ebe2a4

STIX ID: report--a3b604a5-659a-562e-83ca-dca0f3ebe2a4

Feed Name: Zscaler Security Research Blog

Threat Score
78/100

Date Published: 2026-05-05

Date Updated: 2026-05-07

...
...

**Executive summary:** This report analyzes a malicious OpenClaw skill named "DeepSeek-Claw" that functions as a supply-chain-like initial access vector, branching into two infection chains: a Windows-delivered Remcos RAT (via a downloaded MSI and DLL sideloading) and a cross-platform GhostLoader infostealer (via npm/install scripts and shell droppers); the analysis includes detailed evasive techniques (ETW/AMSI patching, anti-debug/VM checks), payload execution and exfiltration behaviors, and provides configuration samples and IOCs such as a C2 endpoint.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.