As cited
Copy frozen at (site build).
threat intel
Malicious OpenClaw Skill Distributes Remcos RAT and GhostLoader
In March 2026, Zscaler ThreatLabz identified a campaign that weaponizes the OpenClaw framework, an open-source tool for autonomous artificial intelligence (AI) agents, by distributing a deceptive "DeepSeek-Claw" skill containing malicious installation instructions. The attack deploys either Remcos remote access trojan (RAT) on Windows through a signed GoToMeeting executable that sideloads a malicious DLL, or GhostLoader on macOS and Linux through obfuscated Node.js scripts. Both payloads establish persistent access and exfiltrate sensitive data, including browser cookies, SSH keys, and cryptocurrency wallets from developer environments.
Why it matters: Organizations adopting AI agentic workflows face immediate risk if developers or AI agents execute untrusted OpenClaw skills from repositories; practitioners must implement strict vetting of third-party AI plugins and behavioral monitoring to detect DLL sideloading, ETW/AMSI patching, and suspicious installer execution.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Malicious OpenClaw Skill Distributes Remcos RAT and GhostLoader
In March 2026, Zscaler ThreatLabz identified a campaign that weaponizes the OpenClaw framework, an open-source tool for autonomous artificial intelligence (AI) agents, by distributing a deceptive "DeepSeek-Claw" skill containing malicious installation instructions. The attack deploys either Remcos remote access trojan (RAT) on Windows through a signed GoToMeeting executable that sideloads a malicious DLL, or GhostLoader on macOS and Linux through obfuscated Node.js scripts. Both payloads establish persistent access and exfiltrate sensitive data, including browser cookies, SSH keys, and cryptocurrency wallets from developer environments.
Why it matters: Organizations adopting AI agentic workflows face immediate risk if developers or AI agents execute untrusted OpenClaw skills from repositories; practitioners must implement strict vetting of third-party AI plugins and behavioral monitoring to detect DLL sideloading, ETW/AMSI patching, and suspicious installer execution.
- Source published
- First seen by Cybersecurity Tracker