logo

Malicious OpenClaw Skill Distributes Remcos RAT and GhostLoader

ID: b73fd9b2-5e4d-53ca-a25f-177e6c803f80

STIX ID: report--b73fd9b2-5e4d-53ca-a25f-177e6c803f80

Feed Name: Security Boulevard

Threat Score
78/100

Date Published: 2026-05-05

Date Updated: 2026-05-08

Author: Mitesh Wani (Security Researcher)

...
...

Zscaler ThreatLabz discovered a campaign abusing an OpenClaw "DeepSeek-Claw" skill to trick AI agents and developers into executing malicious install steps that deliver Remcos RAT on Windows (via a signed GoToMeeting binary sideload and in-memory loader that patches ETW/AMSI) and GhostLoader on macOS/Linux (via obfuscated Node.js/npm scripts); the report provides technical analysis, IOCs (URLs, hashes, C2), and MITRE ATT&CK mappings to aid detection and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.