PULSE NAME
GachiLoader adopts AI skill lure
WHITE AlienVault 2026-04-29 Modified: 2026-04-29
10
IOCs
LOW VOLUME
Threat actors are exploiting AI agent skill formats as a novel attack vector, using convincingly packaged OpenClaw skills to distribute malicious payloads. The latest campaign employs pure social engineering, with skills containing no malicious code themselves but instead tricking users into downloading Windows binaries. The attack leverages a fake GitHub infrastructure hosting GachiLoader, which delivers Rhadamanthys infostealer through fileless injection. The operation uses two delivery mechanisms: Node.js Single Executable Applications and an Electron dropper, both converging on the same payload. GachiLoader employs sophisticated evasion techniques including anti-VM checks, sandbox detection, and privilege escalation, while using a Polygon blockchain smart contract as its C2 resolver for enhanced persistence and obfuscation.
Indicators of Compromise (10)
All FileHash-SHA256 domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 076ba40e7fbf2910dff87f0c25862a70001d8ad81d23d8beae9fb9b29b603829 2026-04-29
FileHash-SHA256 1753d2f90bd4ac6c0c91e76322ae1d0cc8034842a61dc175c7aba3e1aa944c90 2026-04-29
FileHash-SHA256 1831db8fe19efbd12997f63bc76da79858f87995b9ebd8a05757670e5e52c1f2 2026-04-29
FileHash-SHA256 1f24e75c1e6d6777e970f64ebf18e8bf1dd1dcaab692adf4062c8fad6a6df42c 2026-04-29
FileHash-SHA256 539ac28b816ed0ab17879712a460396bd812221b93540590eccdb89c8196db96 2026-04-29
FileHash-SHA256 8abec84db36ee18b3299b5fd9406f8d99a5be7dd0a4e93536e39bb406fce97a6 2026-04-29
FileHash-SHA256 9fb2ea25254ae53f93e0e13abb59a76a6c1ed512cdf1c1deafafa4d2758117f6 2026-04-29
FileHash-SHA256 a981ace958944914e9ea697aff6066d6152820aeea5a6a14a9a7fa6aa31c38a6 2026-04-29
FileHash-SHA256 f583f8307468dc5eacc7be7137dc5c7dbab5fc30ca89b03cf6c67b4de030b05d 2026-04-29
domain onfinality.pro 2026-04-29