logo

How Fake OpenClaw Installers Spread GhostSocks Malware

ID: f532dcd6-5ad8-53e2-8a9f-38fe64767c9c

STIX ID: report--f532dcd6-5ad8-53e2-8a9f-38fe64767c9c

Feed Name: Huntress Blog

Threat Score
75/100

Date Published: 2026-03-04

Date Updated: 2026-04-28

...
...

Huntress investigated malicious GitHub repositories posing as OpenClaw installers (2–10 Feb 2026) that distributed information stealers (Vidar, PureLogs, AMOS) and a GhostSocks backconnect proxy, employed a novel in-memory packer “Stealth Packer”, and abused Bing AI search suggestions to drive victims to malicious releases; the report details the infection chain, persistence mechanisms, C2 infrastructure, and extensive IOCs for detection and remediation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.