CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Malicious OpenClaw Skill Distributes Remcos RAT and GhostLoader

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 6251

As cited

Copy frozen at (site build).

threat intel

Malicious OpenClaw Skill Distributes Remcos RAT and GhostLoader

In March 2026, Zscaler ThreatLabz identified a campaign that weaponizes the OpenClaw framework, an open-source tool for autonomous artificial intelligence (AI) agents, by distributing a deceptive "DeepSeek-Claw" skill containing malicious installation instructions. The attack deploys either Remcos remote access trojan (RAT) on Windows through a signed GoToMeeting executable that sideloads a malicious DLL, or GhostLoader on macOS and Linux through obfuscated Node.js scripts. Both payloads establish persistent access and exfiltrate sensitive data, including browser cookies, SSH keys, and cryptocurrency wallets from developer environments.

Why it matters: Organizations adopting AI agentic workflows face immediate risk if developers or AI agents execute untrusted OpenClaw skills from repositories; practitioners must implement strict vetting of third-party AI plugins and behavioral monitoring to detect DLL sideloading, ETW/AMSI patching, and suspicious installer execution.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Malicious OpenClaw Skill Distributes Remcos RAT and GhostLoader

In March 2026, Zscaler ThreatLabz identified a campaign that weaponizes the OpenClaw framework, an open-source tool for autonomous artificial intelligence (AI) agents, by distributing a deceptive "DeepSeek-Claw" skill containing malicious installation instructions. The attack deploys either Remcos remote access trojan (RAT) on Windows through a signed GoToMeeting executable that sideloads a malicious DLL, or GhostLoader on macOS and Linux through obfuscated Node.js scripts. Both payloads establish persistent access and exfiltrate sensitive data, including browser cookies, SSH keys, and cryptocurrency wallets from developer environments.

Why it matters: Organizations adopting AI agentic workflows face immediate risk if developers or AI agents execute untrusted OpenClaw skills from repositories; practitioners must implement strict vetting of third-party AI plugins and behavioral monitoring to detect DLL sideloading, ETW/AMSI patching, and suspicious installer execution.

VendorsMicrosoftAppleVMwareGitHub
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary