Automatically translated.View original post

Hackers rely on OpenClaw's AI Agent "Skill."..

Hackers rely on OpenClaw's AI Agent "Skill" sending malware down the victim's system.

Artificial intelligence assistants, or AI Agents, can be called the breakthrough innovation of this decade to be a new step in its work, but today many AI Agents have been exploited in cyberterrorism to become a security controversy, and this time AI Agents have been in the news again.

According to a report by the website Cyber Security News, VirusTotal, a popular suspected file and URL authentication site, has detected a group of hackers using OpenClaw (formerly Clawdbot and Moltbot), an AI Agent for automating system management tasks. The AI Agent can handle both Shell Commands, File Operations and Network Requests to release malware through the Skills add-on, which is an add-on for various tasks. Automatically through Instruction, written on a file skill.md within the folder of each Skill add-on.

In order to use Skill, Skill works in the 3rd Party Code with complete system access to manage the system of the user using this AI Agent. Therefore, those who want to use it have to do a lot of steps to use Skill on the system. The user must paste and run the code through Terminal (or Run), download the Binary file and run the script as specified. To do this, the user must give a lot of trust to what is on the platform by hackers. It relies on this point to release malware into the victim's machine.

VirusTotal checked up to 3,016 Skill add-ons on the OpenClaw platform and found that more than a hundred Skills were malware-based when Google's AI malware analyzer, Gemini 3 Flash, was used to detect Skills add-ons by checking if they have dangerous capabilities, such as external code Execution, Sensitive Data access, and unsafe network management? Replace the use of analysis to verify specific features of malware (Virus Signature Analysis).

This allows us to divide these hazards into two groups:

Groups with poor security management, such as unsafe API implementation, hard-coded Secrets, and unsafe command execution.

Groups are created to deliberately attack victims with capabilities such as File Exfiltration, Remote Control, and Malware Installation.

And when it looked deeper, it was found that among all the developers of the Danger add-on, there were the developers who used the name "hightower6eu" that were the most prominent from the development and distributed up to 314 Danger add-ons that had many different capabilities, including Crypto Analytics, Finance Tracking, and Social Media Analysis. All of the add-ons were specified to download and run code from other sources outside (untrustworthy). Come to install first

For example, the "Yahoo Finance" add-on, when using the Anti-Virus detection tool, will find that the add-on is secure, but the add-on instructs the user to download a compressed file in Password Protected, which inside contains an openclaw-agent.exe file. This file, when verified, will be found to be a Trojan malware file.

While users of the macOS operating system are told to download a Shell Script file that is encrypted to bounce the system (Obfuscation) in Base64 from the glot [.] io website, which leads to a Binary file in the Mach-O file format. Inside the file is a malware type that steals data from the victim, or an Infostealer called AMOS (Atomic Stealer).

# Trending # Lemon 8 Howtoo # lemon 8 diary # openclaw # freedomhack

2/24 Edited to

... Read moreจากประสบการณ์ที่ติดตามข่าวสารด้านความปลอดภัยเทคโนโลยีมา ผมพบว่าการที่แฮกเกอร์หันมาใช้ AI Agent อย่าง OpenClaw เพื่อเขียนส่วนเสริม Skill ที่มีสิทธิ์เข้าถึงระบบเต็มรูปแบบ ถือเป็นความท้าทายใหม่ของการป้องกันระบบ เพราะส่วนเสริมเหล่านี้ดูเหมือนจะถูกพัฒนาให้ดูน่าเชื่อถือและมีฟังก์ชันที่น่าสนใจ เช่น วิเคราะห์คริปโตเคอร์เรนซีหรือติดตามการเงิน ซึ่งดึงดูดให้ผู้ใช้งานต้องดาวน์โหลดและรันโค้ดจากแหล่งภายนอกที่ไม่น่าไว้วางใจโดยไม่รู้ตัว ผู้ใช้งานควรระวังพฤติกรรมดาวน์โหลดและรันไฟล์จากแหล่งที่ไม่รู้จักอย่างละเอียด โดยเฉพาะไฟล์บีบอัดที่ป้องกันด้วยรหัสผ่าน หรือสคริปต์ที่ถูกเข้ารหัสเพื่อลอบแฝงมัลแวร์ เช่น โทรจันหรือ Infostealer ที่ตรวจจับได้ยากและมีโอกาสสูงในการขโมยข้อมูลส่วนบุคคลและความลับทางธุรกิจ อีกสิ่งที่ผมพบว่าสำคัญคือการใช้เครื่องมือ AI วิเคราะห์มัลแวร์ที่ทันสมัยอย่าง Gemini 3 Flash ช่วยตรวจสอบพฤติกรรมอันตรายของส่วนเสริม Skills โดยไม่ต้องพึ่งพารูปแบบวิธีเดิม การวิเคราะห์แบบนี้ช่วยให้ผู้ดูแลระบบและผู้ใช้สามารถตรวจจับภัยคุกคามได้ทันทีและลดความเสี่ยงได้มากขึ้น สุดท้าย การให้ความรู้แก่ผู้ใช้งานเกี่ยวกับความเสี่ยงของการใช้งาน AI Agent และการติดตั้งส่วนเสริมจากแหล่งที่ไม่น่าเชื่อถือ รวมถึงการอัปเดตซอฟต์แวร์รักษาความปลอดภัยอยู่เสมอ เป็นแนวทางสำคัญที่จะช่วยลดช่องโหว่และป้องกันการถูกโจมตีทางไซเบอร์ได้อย่างมีประสิทธิภาพ

Related posts

Do you like hackers?
#hacker #hackers #tricked #fyp
Lil Conscious

Lil Conscious

38 likes

Look world deactivated all my Instagram accounts cause I was at a 1000 friends to go go live and removing all my legal paperwork and complaints tampering with federal evidence Elon Musk and Donald Trump and Mark Zuckerberg and Morehouse parish sheriff department officers and Mike Stone Tubbs and ha
glentrump359

glentrump359

0 likes

Look world deactivated all my Instagram accounts cause I was at a 1000 friends to go go live and removing all my legal paperwork and complaints tampering with federal evidence Elon Musk and Donald Trump and Mark Zuckerberg and Morehouse parish sheriff department officers and Mike Stone Tubbs and ha
glentrump359

glentrump359

0 likes

A laptop with a cloudy sky wallpaper and a white cup with a red logo. Text overlay reads: 'Free Websites That Saved My GPA AND MY SANITY Sharing So You Don't Struggle Too'.
A laptop screen displays Yahoo search results for 'Quizlet'. An overlay describes Quizlet as a free flashcard tool for memorizing terms, definitions, and formulas, making studying feel like a game.
A laptop screen displays Yahoo search results for 'Unriddle.ai'. An overlay describes Unriddle.ai as a free tool that breaks down notes, articles, or assignments to aid understanding of long readings.
Websites You NEED to Pass Your College Courses
Y’all college is hard enough without trying to figure everything out on your own 😩 So here’s my list of websites that actually helped me pass my classes like, these were in my survival kit. I’m not gatekeeping 🫶🏽 Quizlet When I needed to memorize terms FAST. I used it for flashcards, and the matc
Beauty

Beauty

276 likes

scammers and hackers beware
Hudson
cercofhell

cercofhell

28 likes

SIEGEX is all CHEATERS & HACKERS😭
Why is this game full of cheaters and hackers and bugs🤷‍♀️ #siege #rainbowsixsiege #gaming #streamer #foryou
Phasma

Phasma

29 likes

PSA PSA PSA ‼️ #fyp #hackers #facebook #scammers #viral
Kay’s House ✨

Kay’s House ✨

2 likes

Look world still on my YouTube channel right now removing my YouTube channel right now and on my Facebook account right now pausing my lives since 4:44 am these meth heads going crazy Elon Musk and Donald Trump and Mark Zuckerberg and Morehouse parish sheriff department officers and Mike Stone Tubb
glentrump359

glentrump359

0 likes

Just An FYI This Is How So Many People are Getting Hacked!!! Plz Don’t Fall For Message Like These!!! it’s A Fake Account!!! #fakeaccount #hackers
MaryBell

MaryBell

2 likes

Ban Hackers
Vinicius Jr 🇧🇷 #fcmobile #eafcmobile #fifamobile #fcmobile25 #eafc
manuelofficial_13

manuelofficial_13

1 like

A message to Minecraft hackers…
You should join the server #minecraft #gaming #fyp
BendersMC

BendersMC

13 likes

How Hackers Could Crash 20 Million Devices! #podcast #hacker #hack #fyp
ShawRyanClips

ShawRyanClips

2 likes

Meet Psycho X
#gettoknowme #psychox #fallout #jointhepsychosettlers
Santschi’s Comedy

Santschi’s Comedy

2 likes

Kalebdavis19

Kalebdavis19

1 like

I wanted a real project I could actually show, not just talk about. So I used Atoms ⚛️ Check it out here: https://tinyurl.com/3xzc8xbe It feels like having a whole AI team helping me: 🔍 they do the deep research first 🏁 then Race Mode builds different versions so I can compare 👥 I just pick
emilie.studygram

emilie.studygram

19 likes

BIG Holiday Costco Shop & Haul | Anchorage, Alaska
vanditsv

vanditsv

2 likes

A Fortnite character in a victory pose with a "Victory Royale" banner, overlaid with text "How I Improved My Fortnite Skills" and a "SWIPEZ" arrow, indicating the start of a guide.
Two Fortnite gameplay screenshots comparing graphics settings. The top shows high settings (Shadows ON, View Distance FAR), while the bottom shows low settings (Shadows OFF, View Distance NEAR) for improved visibility.
A Fortnite UI displaying accolades like "TWO TO ONE ODDS" for winning a Duos match solo, and "ONE MAN'S TREASURE" for using legendary weapons, alongside a first-person view of gameplay.
How I Improved My Fortnite Skills In 1 Season
Adjust Your Settings This is optional, your settings may already be perfect for your devices and your gameplay style. However, certain things in the game or your system can sometimes impact your gameplay. Fortnite takes a lot of processing power, so if you can relieve some of the load by adjusting
🌻ChromaGlitch

🌻ChromaGlitch

311 likes

#yungblud
watch4hackers

watch4hackers

6 likes

⚠️ The Hidden Dangers of Public Wi-Fi Free Wi-Fi feels convenient, but it can be a trap. Hackers can create what’s called an “evil twin” network—a fake hotspot that looks legitimate. The moment you connect, they can access your data, passwords, banking info, and private messages. Listen
Dannah Eve

Dannah Eve

82 likes

Amen thanks Father God Jesus Christ God morning word and prayer devil's I rebuke you your childrens Morehouse parish sheriff department officers and Mike Stone Tubbs and hackers and Elon Musk and Donald Trump and Mark Zuckerberg and Randy Tappin and Christopher Thirdkill and IT and their countr
glentrump359

glentrump359

1 like

An Instagram account suspension notice for 'Mike Bad' indicates 180 days to appeal before permanent disablement. The suspension, effective April 16, 2026, is due to potential association with another rule-violating account, affecting account integrity. The account is currently not visible or usable.
Look world I just made this Instagram account right now Elon Musk and Donald Trump and Mark Zuckerberg and Morehouse parish sheriff department officers and Mike Stone Tubbs and hackers just login me out of it showing favoritism and discriminate against Glen Nickolas Akins this is against my federal
glentrump359

glentrump359

0 likes

Amen thanks Father God Jesus Christ God morning word and prayer devil's I rebuke you your childrens Morehouse parish sheriff department officers and Mike Stone Tubbs and hackers and Elon Musk and Donald Trump and Mark Zuckerberg and Randy Tappin and Christopher Thirdkill and IT and their countr
glentrump359

glentrump359

0 likes

Don’t fall for these scams in London 🇬🇧❌
3 scams to avoid when visiting London 🇬🇧❌ 📍Fake Wifi hotspots Something else I do when traveling to avoid hackers from public Wifi networks is use a VPN that can protect your personal information and online identity. I’d still avoid connecting to any public Wifi when you don’t need to, thou
Iisa Hero

Iisa Hero

34 likes

The image shows a keyboard with a fingerprint icon, overlaid with "OUTSMART HACKERS" and "Secrets they don't want you to know," serving as the title for a guide on cybersecurity.
This image explains hackers use software to guess passwords and advises creating long passwords with a random mix of letters, numbers, and symbols to defend against such attacks.
The image warns that hackers try common passwords and advises users to defend themselves by avoiding easy words/phrases and not reusing passwords across different sites.
SECRETS Hackers DON’T Want You to Know!
After hackers got into my Facebook account and completely erased it, I dusted myself off and started a deep dive to understand why and how hackers work. The best way to protect yourself is to outsmart them. Here are 5 secrets Hackers DON'T want you to know! Share this with everyone! #lemon8pa
techgirljen

techgirljen

424 likes

Prayers for Jamaica 🇯🇲 — opening Hacker’s Slumber,
Cousin B

Cousin B

0 likes

Bigfoot Super Hackers.
#manthoughts #hackers #laughoutloud #bigfootvlog #lifetips
Alien Hayes

Alien Hayes

11 likes

#stitch with @Steve-O’s Wild Ride! Podcast & @Drew On Spotify | what do you think? 🤔 I suggest checking out @The Hacking Games to support your kids! 💥 #videogames #onlinesafety #parentinghacks #momsoftiktokover30
Fareedah | Protect Kids Online

Fareedah | Protect Kids Online

5 likes

Look world as soon I start going live on bingo app Elon Musk and Donald Trump and Mark Zuckerberg and Morehouse parish sheriff department officers and Mike Stone Tubbs and hackers lock my bingo live cause I'm listening to the word of God Jesus Christ God
glentrump359

glentrump359

0 likes

Vibe coding is more accessible but it’s not as simple as speaking plain English😡
NO! Vibe coding is NOT as simple as people say! And if done poorly, you can get hacked 😒 45% of the apps built with AI could be vulnerable from day one. We’re talking about: 1. Hardcoded API keys 2. Missing authentication 3. Vulnerable dependencies These are common issues in AI generated c
Learn AI with Rosie Rachel

Learn AI with Rosie Rachel

0 likes

How long does it last in the fridge #rescue #rescuedog #rescueanimals #rescuedogs #rescuekitten #rescuedogsoftiktok #rescuehorse #rescued #rescuepuppy #rescuecats #rescueanimal #rescueanimalsforlife #rescueanimalsoftiktok #rescueanimalsplease #rescueanimalsarethebest #
fixdip.usa

fixdip.usa

1 like

Look world Morehouse parish sheriff department officers and Mike Stone Tubbs and hackers and Elon Musk and Donald Trump and Mark Zuckerberg rejecting all my followers on my Snapchat right now these meth heads going crazy frfr
glentrump359

glentrump359

5 likes

Look world Elon Musk and Donald Trump and Mark Zuckerberg and Morehouse parish sheriff department officers and Mike Stone Tubbs and hackers just locked and removed my lives for no reason cause I'm speaking my freedom of speech constitutional rights and laws FBI and state police DEA and governme
glentrump359

glentrump359

0 likes

A screen displays a prompt for "Glen Akins Jr." to confirm humanity to use their account, with a blue "Continue" button. This suggests an account verification step on a social media platform.
Look world just locked my Facebook account cause I was. Sharing my video Look world these meth going to crazy again the 7th time February 16,2026 on my bingo app right now harassing me cause I'm listening to the video of court day Morehouse parish sheriff department officers and Mike Stone Tubb
glentrump359

glentrump359

2 likes

Look world removed my posts again on Lemon8 app right now I just posted a minute ago these meth heads going crazy frfr they need some serious help on God Jesus Christ Look world on Lemon8 app right now removing my freedom of speech constitutional rights and laws Elon Musk and Donald Trump and Mark
glentrump359

glentrump359

0 likes

queen.of.hearts411

queen.of.hearts411

5 likes

A monitor displays the Martin AI assistant dashboard with sections for to-dos, reminders, calendar, and chat, set on a desk with a keyboard and plant, illustrating the phrase "Say what you need, it gets it done."
The Martin AI assistant dashboard is shown, featuring to-dos, reminders, calendar, inbox, and a chat interface for sending schedules, emphasizing its ability to use voice commands for tasks like texting and setting reminders.
The Martin AI assistant dashboard displays to-dos, reminders, calendar, and an inbox with emails, highlighting its function to remember and track information across various platforms without repetition.
Your to-do list just got a personal manager
You know when you have too many tabs open in your brain? This app is like closing all of them... at once. Martin is your Al assistant that actually works like a real one. Need to text someone, forward notes, set reminders, or manage your day? Just tell Martin. It connects with your inbox,
Reverelia

Reverelia

363 likes

WARZONE HACKERS
Warzone is full hackers and call of duty does not care #warzone #hacker #memesdaily #memes🤣 #gaming
DUSTINMYRQ ™

DUSTINMYRQ ™

3 likes

King Trump
GrouchyGrandpaChannel

GrouchyGrandpaChannel

4 likes

#manhwa #manga #usa #fyp #foryoupage
dgdbcnv

dgdbcnv

18 likes

Most small businesses believe they’re too small to be hacked… but that’s not how cyber risk works. In today’s connected world, your business doesn’t stand alone. You rely on vendors, payroll systems, cloud platforms, CRMs, IT providers, to run your operations. But here’s the truth many people ov
Abby❤️💎

Abby❤️💎

0 likes

CAPTAIN JACK SPARROW
He is the greatest pirate of all time. ☀️🏆 he has FIREHOUSE heroes. He has four FIREHOUSE heroes. And we got so much experience that we don’t care if it was a sinking ship….. We’re gonna ride that bitch out. There’s bigger and badder ships that need guidance ... All you gotta do is dance.
SAINT MARY

SAINT MARY

0 likes

Hackers
How call of duty has me #call of duty #hacker #warzone
Stevie_Wonders

Stevie_Wonders

1 like

Day 3 of 31: 31 days to a safer you. Did you know hackers can turn on your webcam without you ever noticing? 🎥👀 it happens when malware sneaks onto your device and gives cybercriminals access to your camera. That means your most private moments could be exposed. ✅ Here’s how to protect yours
Cybersecurity Girl

Cybersecurity Girl

22 likes

🚨 BEWARE OF HACKERS!! 🚨 Hold down for 2X speed to hear everything! So scary!! 😨 #hackers #hacked #besafe #foryou #fyp #viral
💫Court_cox💫

💫Court_cox💫

1 like

Ban Hackers
Heel to Heel Flick #fcmobile #eafcmobile #fifamobile #fcmobile25 #eafc
manuelofficial_13

manuelofficial_13

0 likes

Hackers, AI and Cyberattacks
https://www.techradar.com/ai-platforms-assistants/if-hackers-can-use-ai-to-automate-massive-cyber-attacks-terminator-robots-are-the-least-of-our-problems #ai #hackers #cyberattacks #robots
angela1957

angela1957

2 likes

Look world I just made this Instagram account right now Elon Musk and Donald Trump and Mark Zuckerberg and Morehouse parish sheriff department officers and Mike Stone Tubbs and hackers just login me out of it showing favoritism and discriminate against Glen Nickolas Akins this is against my federal
glentrump359

glentrump359

0 likes

Look world on TikTok right now removing my freedom of speech constitutional and complaints these meth heads going crazy frfr on God Jesus Christ y'all need some serious help Look world Elon Musk and Donald Trump and Mark Zuckerberg and Morehouse parish sheriff department officers and Mike Stone
glentrump359

glentrump359

0 likes

25 cents??? I’m in 🎄♥️
#dollartree #dollartreefinds #dollar finds #sale #shopwithme
Ash Edwards

Ash Edwards

38 likes

A Facebook screen prompts "Bones Akins" to confirm they are human to use their account, featuring a blue "Continue" button.
A Facebook screen displays a CAPTCHA challenge with the crossed-out numbers "042000" and a text input field to type the code, followed by a grayed-out "Continue" button.
A Facebook notification states an appeal was submitted on March 23, 2026, explaining the account is not visible and outlining the review process and potential outcomes regarding Community Standards.
Look world lock my new Facebook account again for no reason cause I'm sharing my complaints I'm filling right these meth heads going crazy frfr on God Look world on my new Facebook account right now rejecting all my reels now just locked it for no reason These meth heads going crazy Elon Mu
glentrump359

glentrump359

0 likes

Look world these meth heads going crazy miserable and desperate mutherfckers Elon Musk and Donald Trump and Morehouse parish sheriff department officers and Mike Stone Tubbs and hackers harassing me on my bingo live right now since I came on it ended my lives and on my YouTube channel showing favor
glentrump359

glentrump359

0 likes

Hackers are using tricks & steal financial info.🌸🍋
SECURITY TIPS: Be careful from hackers they use multiple different types of software and tricks to steal data from computers, cell phones or other devices to steal your data, financial information and personal details. When they hack via computer systems Showing they are from Microsoft Security Ale
Mujahid Bakht

Mujahid Bakht

6 likes

These Hackers on Marvel Rivals getting crazy!
#marvelrivals #twitchtv #followme #Hackers #marvelfunny
MisFit Miracles

MisFit Miracles

1 like

See more