Hackers Use Fake OpenClaw Installer to Spread Malware via Bing Search
OpenClaw, an open-source, self-hosted AI agent launched in late January 2026, can read and write files, execute commands, and connect to email and cloud services. Its rapid rise in popularity, combined with users’ tendency to seek installers through search results, allowed fraudulent GitHub projects to exploit the platform’s trusted appearance to infiltrate devices with elevated privileges, increasing the risk of credential, wallet and corporate data theft.
Huntress received its first infection report on February 9, 2026. The victim searched Bing for “OpenClaw Windows” and was directed by an AI-generated result to a malicious GitHub repository posted on February 2. Before it was removed on February 10, the repository used OpenClaw_x64.exe to distribute Vidar and GhostSocks, while a fake macOS guide delivered Atomic Stealer.
All Coverage
4 original reportsThe Backstory
The history behind this eventChinese Hackers Use OpenClaw AI Agent to Launch Automated Cyberattacks
OpenClaw is an AI agent gateway that connects with external tools and services. Chinese hackers have turned it into an attack hub that automatically scans assets, exploits vulnerabilities and verifies financial transactions. The campaign is significant because it focuses on Web3 and fintech services. Stolen AI and payment keys could lead to account takeovers, asset transfers and supply-chain risks.
Cybersecurity firms recently disclosed that the hackers exploited React vulnerabilities to breach targets and steal keys for AI and payment services. They then queried blockchain intelligence APIs to identify assets that could be monetized, creating an end-to-end automated workflow. OpenClaw backend logs have recorded more than 45,000 exploit attempts. As of July 20, 2026, no exact loss figure or list of affected institutions had been disclosed.
OpenClaw AI Agent Software Goes Viral in China, Triggering Cybersecurity Warnings
OpenClaw, created by Austrian engineer Peter Steinberger and released as open source in January 2026, can handle email, manage schedules and book flights. Its popularity has sparked a “raising lobsters” craze in China. The software requires access to files and environment variables and can call APIs. Those elevated system privileges also expose personal credentials, corporate data and industrial control systems to the risk of leaks or takeover.
China’s National Computer Network Emergency Response Technical Team/Coordination Center warned on March 10, 2026, that malicious instructions embedded in webpages could cause product keys to leak. Remote uninstallation services priced at 199 yuan (about NT$920) quickly appeared. On March 22, the center and the Cyber Security Association of China issued the first secure-use guidelines, calling for OpenClaw to be isolated on dedicated devices or virtual machines and denied administrator privileges. Financial institutions, government agencies and several colleges and universities have also successively restricted its use.
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.