Malicious OpenClaw Skill Distributes Remcos RAT and GhostLoader
ID: b73fd9b2-5e4d-53ca-a25f-177e6c803f80
STIX ID: report--b73fd9b2-5e4d-53ca-a25f-177e6c803f80
Feed Name: Security Boulevard
Threat Score
Zscaler ThreatLabz discovered a campaign abusing an OpenClaw "DeepSeek-Claw" skill to trick AI agents and developers into executing malicious install steps that deliver Remcos RAT on Windows (via a signed GoToMeeting binary sideload and in-memory loader that patches ETW/AMSI) and GhostLoader on macOS/Linux (via obfuscated Node.js/npm scripts); the report provides technical analysis, IOCs (URLs, hashes, C2), and MITRE ATT&CK mappings to aid detection and mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
