Skip to content

ADMIN.FOUNDATION

  • OpenClaw AI Agent Skills Abused by Threat Actors to Deliver Malware

    ·

    Cyber Attack News, cyber security, Cyber Security News

    Hundreds of malicious skills designed to deliver trojans, infostealers, and backdoors disguised as legitimate automation tools.

    VirusTotal has uncovered a significant malware distribution campaign targeting OpenClaw, a rapidly growing personal AI agent ecosystem.

    OpenClaw, previously known as Clawdbot and briefly as Moltbot, is a self-hosted AI agent that executes real system actions, including shell commands, file operations, and network requests.

    OpenClaw Skill Abuse Campaign

    The platform extends functionality through skills, small packages built around SKILL.md files that users discover and install from ClawHub, the public marketplace for OpenClaw extensions.

    Users run untrusted code during setup(source : VirusTotal)
    Users run untrusted code during setup (source: VirusTotal)

    While this architecture enables powerful automation capabilities, it creates a dangerous attack surface.

    Skills run as third-party code with complete system access, often requiring users to paste commands into terminals, download binaries, or execute scripts during setup.

    Threat actors are exploiting this trust model to distribute malware through seemingly helpful tools.

    A Mach-O binary flagged by 16 engines( source : VirusTotal)
    A Mach-O binary flagged by 16 engines (source: VirusTotal)

    VirusTotal Code Insight has analyzed over 3,016 OpenClaw skills, and hundreds of them exhibit malicious characteristics.

    Base64-obfuscated macOS script( source : VirusTotal)
    Base64-obfuscated macOS script( source : VirusTotal)

    The analysis, powered by Gemini 3 Flash, examines security behaviors such as external code execution, sensitive data access, and unsafe network operations, rather than relying solely on traditional antivirus signatures.

    Gemini 3 Pro flags it as AMOS infostealer( source : VirusTotal)
    Gemini 3 Pro flags it as AMOS infostealer( source : VirusTotal)

    Security researchers identified two distinct threat categories: skills that contain poor security practices, such as insecure APIs, hardcoded secrets, and unsafe command execution.

    Intentionally malicious skills designed for data exfiltration, remote control, and malware installation.

    Prolific Malware Publisher

    A particularly concerning case involves ClawHub user “hightower6eu,” who published 314 malicious skills covering crypto analytics, finance tracking, and social media analysis.

    Each skill instructs users to download and execute external code from untrusted sources during setup. One example, a “Yahoo Finance” skill, appeared clean to traditional antivirus engines.

    However, VirusTotal Code Insight identified instructions directing Windows users to download a password-protected ZIP file containing openclaw-agent.exe, which multiple vendors have detected as a packed trojan.

    For macOS users, the skill pointed to a Base64-obfuscated shell script on glot.io. That downloaded and executed a Mach-O binary identified as Atomic Stealer (AMOS), an infostealer targeting passwords, browser credentials, and cryptocurrency wallets.

    Organizations and users should treat skill folders as trusted-code boundaries, implement sandboxed execution, and avoid skills that require shell commands or binary downloads.

    Marketplace operators should implement publish-time scanning to flag remote execution and obfuscated scripts.

    VirusTotal is exploring integration with OpenClaw’s publishing workflow to provide automated security analysis during skill submission.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post OpenClaw AI Agent Skills Abused by Threat Actors to Deliver Malware appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Malicious Google Play App With 50K+ Downloads Spreads Anatsa Banking Trojan

    ·

    cyber security, Cyber Security News

    A malicious application on the Google Play Store masquerading as a legitimate document reader. The deceptive application, which has accumulated over 50,000 downloads, functions as a dropper for the notorious Anatsa banking trojan, a sophisticated malware strain known for targeting financial institutions and compromising user banking credentials. The malicious app leverages social engineering tactics by […]

    The post Malicious Google Play App With 50K+ Downloads Spreads Anatsa Banking Trojan appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Hikvision Wireless AP Flaw Could Let Attackers Run Arbitrary Commands

    ·

    CVE/vulnerability, cyber security, Cyber Security News, vulnerability

    Hikvision has disclosed a high-severity command execution vulnerability affecting multiple wireless access point models, potentially allowing authenticated attackers to execute arbitrary commands on affected devices. The company released an advisory on January 30, 2026, detailing the security flaw and urging customers to apply patches immediately. Vulnerability Details The vulnerability, tracked as CVE-2026-0709, stems from insufficient input […]

    The post Hikvision Wireless AP Flaw Could Let Attackers Run Arbitrary Commands appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Mozilla Adds One-Click Option to Disable Generative AI Features in Firefox

    ·

    Mozilla on Monday announced a new controls section in its Firefox desktop browser settings that allows users to completely turn off generative artificial intelligence (GenAI) features. “It provides a single place to block current and future generative AI features in Firefox,” Ajit Varma, head of Firefox, said. “You can also review and manage individual AI features if you choose to use them. This

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • APT28 Exploits Active Microsoft Office Zero-Day to Deliver Malware

    ·

    cyber security, Cyber Security News, Malware, Microsoft

    The Russia-linked advanced persistent threat group APT28 has been observed actively exploiting a zero-day vulnerability in Microsoft Office to deliver malware through a sophisticated multi-stage attack campaign. Security researchers from Zscaler ThreatLabz identified this new operation, dubbed Operation Neusploit, targeting users across Central and Eastern Europe with weaponized RTF documents. The campaign specifically targeted Ukraine, […]

    The post APT28 Exploits Active Microsoft Office Zero-Day to Deliver Malware appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Critical Flaws in KiloView Devices Enable Complete Admin Takeover

    ·

    CVE/vulnerability, cyber security, Cyber Security News, vulnerability

    The Cybersecurity and Infrastructure Security Agency (CISA) has disclosed a critical vulnerability affecting multiple versions of KiloView Encoder Series devices, warning that unauthenticated attackers could gain full administrative access. Issued under alert code ICSA-26-029-01 on January 29, 2026, the flaw carries a severe CVSS v3 score of 9.8, indicating extreme risk to affected infrastructure. The […]

    The post Critical Flaws in KiloView Devices Enable Complete Admin Takeover appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Apache Syncope Vulnerability Allows Attackers to Hijack Active User Sessions

    ·

    CVE/vulnerability, cyber security, Cyber Security News, vulnerability

    Apache Syncope, a popular open-source identity and access management platform, has disclosed a critical XML External Entity (XXE) vulnerability in its Console component. The vulnerability, tracked as CVE-2026-23795, allows authenticated administrators to execute XXE attacks and extract sensitive data from affected systems. Security researchers Follycat and Y0n3er discovered the flaw, which affects multiple versions of […]

    The post Apache Syncope Vulnerability Allows Attackers to Hijack Active User Sessions appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Notepad++ Hosting Breach Attributed to China-Linked Lotus Blossom Hacking Group

    ·

    A China-linked threat actor known as Lotus Blossom has been attributed with medium confidence to the recently discovered compromise of the infrastructure hosting Notepad++. The attack enabled the state-sponsored hacking group to deliver a previously undocumented backdoor codenamed Chrysalis to users of the open-source editor, according to new findings from Rapid7. The development comes shortly

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Notepad++ Attack Breakdown Reveals Sophisticated Malware and Actionable IoCs

    ·

    CVE/vulnerability, cyber security, Cyber Security News, vulnerability

    A complex espionage campaign attributed to Chinese APT group Lotus Blossom, active since 2009. The investigation uncovered a sophisticated compromise of Notepad++ distribution infrastructure that delivered Chrysalis, a previously undocumented custom backdoor with extensive remote access capabilities. The attack chain began at IP address 95.179.213.0, where execution of notepad++.exe and GUP.exe preceded download of a […]

    The post Notepad++ Attack Breakdown Reveals Sophisticated Malware and Actionable IoCs appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Phishing Scam Uses Clean Emails and PDFs to Steal Dropbox Logins

    ·

    Cyber Attack, cybersecurity, Dropbox, Fraud, Password, PDF, Phishing, Phishing Scam, Privacy, SCAM, Security
    A multi-stage phishing campaign is targeting business users by exploiting Vercel cloud storage, PDF attachments, and Telegram bots to steal Dropbox credentials.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

Previous Page
1 … 528 529 530 531 532 … 1,054
Next Page

ADMIN.FOUNDATION

cybersecurity / defense / intelligence