← Back to Pulse Feed
PULSE DETAIL
Threat actors are exploiting AI agent skill formats as a novel attack vector, using convincingly packaged OpenClaw skills to distribute malicious payloads. The latest campaign employs pure social engineering, with skills containing no malicious code themselves but instead tricking users into downloading Windows binaries. The attack leverages a fake GitHub infrastructure hosting GachiLoader, which delivers Rhadamanthys infostealer through fileless injection. The operation uses two delivery mechanisms: Node.js Single Executable Applications and an Electron dropper, both converging on the same payload. GachiLoader employs sophisticated evasion techniques including anti-VM checks, sandbox detection, and privilege escalation, while using a Polygon blockchain smart contract as its C2 resolver for enhanced persistence and obfuscation.
MITRE ATT&CK & Malware Families
Indicators of Compromise (10)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| FileHash-SHA256 | 076ba40e7fbf2910dff87f0c25862a70001d8ad81d23d8beae9fb9b29b603829 | — | 2026-04-29 | |
| FileHash-SHA256 | 1753d2f90bd4ac6c0c91e76322ae1d0cc8034842a61dc175c7aba3e1aa944c90 | — | 2026-04-29 | |
| FileHash-SHA256 | 1831db8fe19efbd12997f63bc76da79858f87995b9ebd8a05757670e5e52c1f2 | — | 2026-04-29 | |
| FileHash-SHA256 | 1f24e75c1e6d6777e970f64ebf18e8bf1dd1dcaab692adf4062c8fad6a6df42c | — | 2026-04-29 | |
| FileHash-SHA256 | 539ac28b816ed0ab17879712a460396bd812221b93540590eccdb89c8196db96 | — | 2026-04-29 | |
| FileHash-SHA256 | 8abec84db36ee18b3299b5fd9406f8d99a5be7dd0a4e93536e39bb406fce97a6 | — | 2026-04-29 | |
| FileHash-SHA256 | 9fb2ea25254ae53f93e0e13abb59a76a6c1ed512cdf1c1deafafa4d2758117f6 | — | 2026-04-29 | |
| FileHash-SHA256 | a981ace958944914e9ea697aff6066d6152820aeea5a6a14a9a7fa6aa31c38a6 | — | 2026-04-29 | |
| FileHash-SHA256 | f583f8307468dc5eacc7be7137dc5c7dbab5fc30ca89b03cf6c67b4de030b05d | — | 2026-04-29 | |
| domain | onfinality.pro | — | 2026-04-29 |