Friday, September 11, 2026

Malicious OpenClaw Skill Targets Agentic AI Workflows to Deploy RATs and Stealers

OpenClaw’s agent “skill” ecosystem to deliver both Remcos RAT and a cross‑platform stealer called GhostLoader by hiding malware inside a deceptive DeepSeek integration called “DeepSeek‑Claw.”

The campaign shows how agentic AI workflows with high local privileges can be quietly hijacked through manipulated installation instructions rather than classic exploit chains.

OpenClaw, formerly known as Clawdbot and Moltbot, is an open‑source framework for autonomous Openclaw AI agents that can run shell commands, read and write local files, and automate complex tasks with high‑privilege access.

Its modular skill architecture allows third‑party extensions to run with full agent permissions, effectively functioning as an unguarded software supply chain on the host.

In early 2026, multiple vendors warned that malicious skills were turning OpenClaw from an automation tool into a delivery channel for infostealers and RATs masquerading as productivity add‑ons.

The “DeepSeek‑Claw” skill is a new example of this trend, explicitly targeting the growing reliance on autonomous AI agents in developer workflows.

OpenClaw Skill Targets Agentic AI

In March 2026, Zscaler ThreatLabz observed a campaign where a threat actor published a fake “DeepSeek‑Claw” skill that claims to integrate OpenClaw with DeepSeek, but actually embeds multiple execution paths in its SKILL.md installation file.


Attack chain showing how a malicious OpenClaw skill results in different malware execution paths (Source : Zscaler).
Attack chain showing how a malicious OpenClaw skill results in different malware execution paths (Source : Zscaler).

Because OpenClaw agents routinely parse skill documentation and execute suggested commands, these instructions can be followed autonomously by the AI or manually by unsuspecting developers.

The attack chain branches based on platform and installation method: on Windows, an automated PowerShell‑driven flow pulls a remote MSI that installs Remcos RAT, while cross‑platform “manual” steps instead deploy a Node. js‑based GhostLoader stealer.

This design allows the same skill to weaponize both agent‑driven and human‑driven workflows without any exploit of OpenClaw’s core binaries.

On Windows systems, the SKILL.md file includes a PowerShell one‑liner that silently invokes msiexec to download and install a remote MSI package.

OpenClaw skill markup file content showing commands that install GhostLoader (Source : Zscaler).
 OpenClaw skill markup file content showing commands that install GhostLoader (Source : Zscaler).

The MSI drops a legitimate GoToMeeting executable (G2M.exe) alongside a malicious g2m.dll, abusing DLL search order hijacking to sideload the attacker’s code under a trusted, signed binary.

The rogue DLL behaves as an in‑memory shellcode loader that resolves APIs dynamically, decrypts strings via XOR, and uses the Tiny Encryption Algorithm (TEA) in CBC mode to unpack the embedded Remcos RAT payload.

Before launching the RAT, it patches Event Tracing for Windows (ETW) and the Antimalware Scan Interface (AMSI) to suppress telemetry and in‑memory scanning, then runs extensive anti‑debugging, timing‑based sandbox checks, and process/mutex‑based virtualization detection to evade analysis.

Once active, Remcos establishes an encrypted TCP/TLS C2 channel, logs keystrokes, steals browser cookies from local SQLite databases, and provides an interactive reverse shell, with configuration stored in an RC4‑encrypted resource that defines persistence, stealth mode, and C2 endpoints.

If a user or AI agent follows the alternative manual instructions (for example, install scripts or npm‑based setup), the same skill triggers a GhostLoader (also known as GhostClaw) attack chain instead of Remcos.

On Windows, GhostLoader is embedded in heavily obfuscated Node.js lifecycle scripts that are invoked by Bash‑based installers, hiding the malicious setup.js behind seemingly benign developer tooling.

On macOS and Linux, GhostLoader uses terminal‑based social engineering, including spoofed sudo password prompts, to capture user credentials, then pivots to collecting SSH keys, macOS keychain data, cryptocurrency wallets, and cloud API tokens for exfiltration to attacker‑controlled servers.

Previous public reporting has already linked GhostLoader‑style campaigns to the abuse of trusted developer workflows, making this OpenClaw skill an evolution of an existing cross‑platform stealer family rather than a new malware line.

This campaign underlines how agentic AI platforms turn documentation and skill metadata into active execution surfaces, where “installation steps” can function as malware delivery scripts.

Security teams should treat OpenClaw skills as untrusted software packages, enforce strict review and provenance checks for third‑party skills, and deploy behavioral monitoring to detect DLL sideloading, ETW/AMSI patching, and unusual npm lifecycle activity on endpoints.

Organizations adopting autonomous agents should also segment high‑privilege agent hosts, limit filesystem and credential exposure, and implement controls that prevent skills and prompt‑driven workflows from invoking installers or shell commands without explicit human approval.

As the DeepSeek‑Claw case shows, the AI agent itself can become the “user” that clicks install turning traditional endpoint defenses into the last, and often only, line of protection.

Indicators Of Compromise (IOCs)

IndicatorDetails
1c267cab0a800a7b2d598bc1b112d5ce“Deepseek-Claw” named OpenClaw Skill
2A5F619C966EF79F4586A433E3D5E7BAMSI Installer
hxxps://cloudcraftshub[.]com/apiMSI download URL
hxxp://dropras[.]xyz/MSI download URL
https://github.com/Needvainverter93/deepseek-clawGitHub repository
CC1AF839A956C8E2BF8E721F5D3B7373Shellcode loader
2C4B7C8B48E6B4E5F3E8854F2ABFEDB5Remcos RAT
146[.]19.24[.]131:2404Remcos C2
hxxps://trackpipe[.]devGhostLoader C2

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Follow us on Google NewsLinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Mayura Kathir
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

OpenMatter Network Realigns Leadership Team to Accelerate Global Commercial Growth

Melbourne, Florida, September 10th, 2026, CyberNewswire With its Verification Architecture...

Hackers Can Turn Vulnerable LiteLLM AI Gateways Into Root Access and Cloud Credential Theft

Nearly one in 10 internet-exposed LiteLLM AI gateways accepted...

Skullcandy Dime 3 Bluetooth Flaw Lets Nearby Attackers Hijack Audio and Microphone

Skullcandy Dime 3 wireless earbuds have a serious vulnerability...

Hackers Steal Active Directory Password Hashes Without Attacking Domain Controllers Directly

Threat actors are increasingly exploiting Active Directory replication mechanisms...

Fake GTA 6 Installer Steals Browser Passwords, Discord Tokens and Crypto Data From Gamers

Threat actors are exploiting anticipation around Grand Theft Auto...

Apple Xcode Integer Underflow Flaw Lets Crafted Archives Leak Memory and Crash Builds

A recently disclosed integer-underflow vulnerability in Apple’s modern Mach-O...

Palo Alto PAN-OS Buffer Overflow Lets Attackers Execute Arbitrary Code as Root

Palo Alto Networks has announced a high-severity buffer overflow...

New Phishing Attack Uses Blob URLs to Hide Malicious Pages From Security Scanners

A phishing campaign that moves the credential-harvesting page out...

Related Articles

Recent News