PULSE NAME
Malicious OpenClaw Skill Distributes Remcos RAT and GhostLoader
WHITE AlienVault 2026-05-05 Modified: 2026-05-06
13
IOCs
MEDIUM VOLUME
In March 2026, threat actors weaponized the OpenClaw AI agent framework by publishing a deceptive "DeepSeek-Claw" skill. This skill embedded malicious installation instructions designed to trick AI agents and developers into executing hidden payloads. On Windows systems, a PowerShell command downloads an MSI package containing a legitimate signed GoToMeeting executable that sideloads a malicious DLL. This loader patches ETW and AMSI for evasion, then decrypts and executes Remcos RAT using TEA encryption, enabling remote access and data theft including keylogging and cookie stealing. An alternate execution path for macOS and Linux delivers GhostLoader through obfuscated Node.js scripts, harvesting credentials via fake sudo prompts and exfiltrating SSH keys, cryptocurrency wallets, and cloud API tokens. This campaign represents an emerging threat vector exploiting autonomous AI workflows and developer trust in open-source frameworks.
Indicators of Compromise (5 / 13 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 1c267cab0a800a7b2d598bc1b112d5ce 2026-05-05
FileHash-MD5 2a5f619c966ef79f4586a433e3d5e7ba 2026-05-05
FileHash-MD5 2c4b7c8b48e6b4e5f3e8854f2abfedb5 2026-05-05
FileHash-MD5 82536825e700f4c863238a90dd314687 2026-05-05
FileHash-MD5 cc1af839a956c8e2bf8e721f5d3b7373 2026-05-05