TI Mindmap HUB
Threat Intelligence Report

“Malware, from the Outside!”: How a Threat Actor Used Fake OpenClaw Installers to Infect Systems with GhostSocks and Information Stealers

📅 March 9, 2026 📰 www.huntress.com 🔍 0 CVE(s) referenced

Threat actors exploited the popularity of OpenClaw by poisoning Bing AI search results with malicious GitHub repositories hosting fake installers, which deployed stealthy information stealers and GhostSocks proxy malware to compromise both Windows and macOS systems, enabling credential theft and bypassing anti-fraud protections.

vendor

Sign in to access the full report including:
detailed analysis, IOCs, MITRE ATT&CK mapping, and STIX bundle.

🔐 Sign In to Read Full Report

You'll need to accept our Terms of Service to access the platform.

📊 Visual Mindmap
🎯 IOC Extraction
⚔️ MITRE ATT&CK TTPs
📦 STIX 2.1 Bundle