Linux Rootkit, macOS Crypto Stealer, WebSocket Skimmers and More – CYBERDEFENSA.MX

Rough Monday.

Somebody poisoned a trusted download again, somebody else turned cloud servers into public housing, and a few crews are still getting into boxes with bugs that should’ve died years ago — the same old holes, same lazy access paths, same “how the hell is this still open” feeling. One report this week basically reads like a guy tripped over root access by accident and decided to stay there.

The weird part is how normal this all sounds now. Fake updates. Quiet backdoors. Remote tools are used like skeleton keys. Forum rats swapping stolen access while defenders burn another weekend chasing logs and praying the weird traffic is just monitoring noise. The Internet’s held together with duct tape and bad sleep.

Anyway, Monday recap time. Same fire. New smoke.

⚡ Threat of the Week

Ivanti EPMM and Palo Alto Networks PAN-OS Flaws Under Attack—Ivanti warned customers that attackers have successfully weaponized CVE-2026-6973, an improper input validation defect in Endpoint Manager Mobile (EPMM) that allows authenticated users with administrative privileges to run code remotely. The company did not say when the first instance of exploitation occurred, or precisely how many customers have been impacted. In a related development, attackers are actively exploiting a zero-day vulnerability affecting some Palo Alto Networks’ customers’ firewalls. As in the case of Ivanti, Palo Alto Networks did not say when or how it became aware of active exploitation, but said threat actors may have attempted to unsuccessfully exploit a recently disclosed critical security flaw as early as April 9, 2026. The memory corruption vulnerability, tracked as CVE-2026-0300, affects the authentication portal of PAN-OS and allows unauthenticated attackers to run code with root privileges on the PA-Series and VM-Series firewalls. Attack surface management platform Censys said it detected about 263,000 Internet-exposed hosts running PAN-OS. Patches are expected to be released starting May 13, 2026. 

🔔 Top News

  • New Quasar Linux RAT Spotted—Attackers have found a new way to turn Linux systems into entry points for a supply chain or cloud infrastructure breach that are resilient to takedowns. The new malware framework, dubbed Quasar Linux or QLNX, is a modular Linux remote access trojan (RAT) that can harvest data from compromised systems. But what sets it apart is its use of a peer-to-peer (P2P) mesh capability that turns individual compromises into an interconnected infection network, making the campaign difficult to kill and allowing infected hosts to communicate with one another rather than relying entirely on centralized servers. QLNX also combines kernel-level rootkit functionality, PAM-based authentication backdoors, and persistence mechanisms to stay hidden on compromised systems while enabling persistent access. It also hides malicious processes under names that mimic legitimate Linux services and system binaries to blend into routine workflows. «Quasar Linux RAT (QLNX) is a comprehensive Linux implant that combines remote access capabilities with advanced evasion, persistence, keylogging, and credential harvesting features,» Trend Micro said. «The malware carries embedded C source code for both its PAM backdoor and LD_PRELOAD rootkit as string literals within the binary.»
  • PCPJack Replaces TeamPCP Malware to Steal Cloud Secrets—An unknown threat actor has launched a campaign to systematically clean up environments infected by the infamous TeamPCP hacking group and drop its own malicious tools to steal credentials from cloud, container, developer, productivity, and financial services for financial gain. Active since late April, the campaign is also capable of propagating itself by moving laterally both inside of a network and to other targets by breaking into open and exploitable cloud infrastructure. The broad credential harvesting sweep allows the malware to hack into more cloud servers and propagate the infection in a worm-like manner, while also rooting out any processes and artifacts belonging to TeamPCP. The external propagation is achieved by downloading parquet files from Common Crawl for target discovery. While threat actors aiming for cloud environments have long built methods to delete competing malware, particularly in cryptojacking campaigns, the lack of a miner and its specific targeting of TeamPCP tooling has raised the possibility that it may be someone who was previously associated with the group, is part of a rival crew, or is an unrelated third-party mimicking TeamPCP’s tradecraft.
  • MuddyWater Uses Chaos Ransomware as Decoy in New Attack—An Iranian state-sponsored espionage group pretended to be a regular ransomware gang in a new ransomware attack detected in early 2026. The Iranian hackers known as MuddyWater disguised their operations as a Chaos ransomware attack, relying on Microsoft Teams social engineering to gain access and establish persistence within a victim environment. Although the attack involved reconnaissance, credential harvesting, and data exfiltration, no file-encrypting ransomware was deployed, which is inconsistent with Chaos attacks. The victim was also added to the Chaos ransomware data leak site, but infrastructure and code-signing certificate evidence indicate the activity was likely used as a cover to mask the threat actor’s true espionage goals and to complicate attribution. Rapid7 told The Hacker News that there is no evidence to suggest that MuddyWater is operating as an affiliate of Chaos.
  • DAEMON Tools Supply Chain Attack Leads to QUIC RAT—Hackers compromised installers of DAEMON Tools in a supply chain attack that affected users in more than 100 countries. The malicious versions, first observed in early April, impacted multiple releases of the software that were installed on thousands of machines across Russia, Brazil, Turkey, Spain, Germany, France, Italy, and China. The operation appears to be targeted. Most victims received only a data miner designed to gather system data, while a second, more advanced shellcode loader was deployed to just a handful of targets, including organizations in retail, scientific, government, and manufacturing organizations in Russia, Belarus, and Thailand. It’s suspected that the attackers likely used the initial data collection to profile infected systems before selectively deploying an implant codenamed QUIC RAT. The malware was deployed against only one known target, an unidentified educational institution in Russia. Kaspersky said the malicious code included Chinese-language elements, suggesting the attackers are familiar with the language, but stopped short of attributing the campaign to a specific group. 
  • Cybercrime Groups Use Vishing for Data Theft and Extortion—An active phishing campaign has been observed targeting multiple vectors since at least April 2025, with legitimate Remote Monitoring and Management (RMM) software as a way to establish persistent remote access to compromised hosts. The activity, which targets organizations across multiple industries, highlights a growing trend where attackers weaponize legitimate IT management tools to bypass security controls and maintain persistence on compromised systems. What makes the campaign noteworthy is its deliberate avoidance of traditional malware in favor of two commercially available remote monitoring and management (RMM) tools, SimpleHelp and ScreenConnect, for persistent control over victim machines. The abuse of RMM tools by bad actors has surged in recent years as they offer a low-friction way to gain access to and maintain persistence on a victim environment. Because of how ubiquitous they are in enterprise environments, the tools are flagged as malicious, allowing the attackers to blend in with normal operations.

🔥 Trending CVEs

Bugs drop weekly, and the gap between a patch and an exploit is shrinking fast. These are the heavy hitters for the week: high-severity, widely used, or already being poked at in the wild.

Check the list, patch what you have, and hit the ones marked urgent first — CVE-2026-6973 (Ivanti Endpoint Manager Mobile), CVE-2026-0300 (Palo Alto Networks PAN-OS), CVE-2026-29014 (MetInfo), CVE-2026-22679 (Weaver E-cology), CVE-2026-4670, CVE-2026-5174 (Progress MOVEit Automation), CVE-2026-43284, CVE-2026-43500 (Linux Kernel), CVE-2026-7482 (Ollama), CVE-2026-42248, CVE-2026-42249 (Ollama for Windows), CVE-2026-29201, CVE-2026-29202, CVE-2026-29203 (cPanel and Web Host Manager), CVE-2026-23918 (Apache HTTP Server), CVE-2026-42778, CVE-2026-42779 (Apache MINA), CVE-2026-2005, CVE-2026-2006 (PostgreSQL pgcrypto), CVE-2026-32710 (MariaDB), CVE-2026-23863, CVE-2026-23866 (Meta WhatsApp), CVE-2026-29146 (Apache Tomcat), CVE-2026-1046 (Mattermost Desktop), CVE-2026-0073 (Google Android), CVE-2026-20188 (Cisco Crosswork Network Controller and Network Services Orchestrator), CVE-2026-20185 (Cisco SG350 and SG350X Series Managed Switches), CVE-2026-20034, CVE-2026-20035 (Cisco Unity Connection), CVE-2026-7896, CVE-2026-7897, CVE-2026-7898, CVE-2026-5865 (Google Chrome), CVE-2025-68670 (xrdp), CVE-2026-23864 (React Server Components), CVE-2026-23870, CVE-2026-44575, GHSA-26hh-7cqf-hhc6, CVE-2026-44579, CVE-2026-44574, CVE-2026-44578, CVE-2026-44573 (Next.js), CVE-2026-26129, CVE-2026-26164 (Microsoft M365 Copilot), CVE-2026-33111 (Microsoft Copilot Chat), CVE-2026-44843 (LangChain), and CVE-2026-33309 (Langflow).

🎥 Cybersecurity Webinars

  • The Hidden Attack Paths Your AppSec Tools Completely Miss in 2026 → This webinar shows the real attack paths that most AppSec tools miss — from code and CI/CD pipelines to cloud setups, dependencies, and secrets. See how attackers combine small weaknesses into big breaches, and learn simple ways to find and stop them. With Wiz experts Mike McGuire and Salman Ladha.
  • AI-Powered DDoS Attacks Are Here — And They’re Smarter, Faster & Deadlier in 2026 → Attackers are now using AI to launch DDoS attacks that are faster, smarter, and much harder to stop. This webinar shows how they instantly spot weak spots, create new attack methods, and dramatically increase success rates — plus easy ways defenders can fight back using smarter AI tools and proactive protection. Perfect for security leaders who want to stay ahead.

📰 Around the Cyber World

  • JDownloader Website Compromised in Supply Chain Attack —The website for JDownloader, an open-source download management tool, was compromised last week to distribute malicious Windows and Linux installers. The compromise occurred on May 6, 2026, at 12:01 a.m. UTC. While the Linux version embeds malicious shell code, the Windows version has been found to serve a Python-based remote access trojan (RAT) that enlists the compromised device in a bot network and runs arbitrary Python code supplied by the operator, per researcher Thomas Klemenc. «The attack has modified alternative download pages and exchanged links and details,» the developer behind JDownloader said in a post on Reddit. «The bad ones are missing digital signatures and as such [Microsoft] SmartScreen will block/warn the execution of it.» Further investigation uncovered that the attack vector was an «unpatched security bug,» although it’s not clear which vulnerability was exploited by the threat actor to tamper with the site.
  • Operation HookedWing Targets Over 500 Organizations —A long-running phishing campaign dating back to 2022 has stolen 2,000 credentials belonging to users from over 500 different organizations. According to SOCRadar, the campaign has mostly affected aviation, public administration, energy, and critical infrastructure. «The breadth of targeting, combined with the campaign’s longevity, points to a resource-capable operation rather than opportunistic activity,» it said. The activity has been codenamed Operation HookedWing. The attack uses phishing emails with lures related to human resources, Microsoft, or Google to direct users to fake landing pages hosted on GitHub.io and Vercel, capture entered credentials via an injected form, and exfiltrate them to servers compromised or created by the threat actor. More than 20 distinct command-and-control (C2) domains and 100 distribution domains have been identified.
  • Uptick in Use of Vercel for Phishing Campaigns —Threat actors are increasingly using Vercel to create large numbers of realistic phishing websites that impersonate well-known brands. «Threat actors are able to redeploy phishing campaigns with ease if a web page is taken down,» Cofense said. «Vercel abuse has increased significantly over time and is likely to continue increasing as minimally skilled threat actors start using cheap or free force multipliers.»
  • New ConsentFix V3 Attack Automates Microsoft Account Hijacking —Push Security said it identified a member of the XSS criminal forum advertising a new toolkit dubbed ConsentFix v3 that brings together ClickFix-style social engineering with OAuth consent phishing to hijack Microsoft accounts. «ConsentFix v3 allows users to instrument the entire attack chain, enabling users to spin up ConsentFix infrastructure, create believable personas with which to interact with victims, craft and manage email campaigns, and automate the process of exchanging the captured OAuth token for session and refresh tokens to establish access to the compromised account,» Push Security said. The attack uses Cloudflare Workers for hosting the phishing pages, ZoomInfo for target identification, Dropbox for PDF hosting, and Pipedream as an exfiltration channel.
  • Workplace Fraud Trends in 2026 —A new report from Cifas has found that 13% of employees said: «they have either sold their company login details to a former colleague, or know someone who has, in the past 12 months.» Another 13% of respondents believed selling access to company systems was justifiable. «Selling login details might seem insignificant to those involved, but it can open the door to serious fraud and financial harm,» Cifas said. «These findings show how vital it is for organisations to build fraud‑aware cultures, where employees at all levels understand their responsibilities and the consequences of their actions.»
  • India Pushes for Sovereign Hosting of Anthropic’s Claude AI Models —According to a report from MoneyControl, the Indian government is said to be pushing for sovereign hosting of Anthropic’s Claude artificial intelligence (AI) models within India. Officials have argued that advanced AI systems meant for sensitive sectors such as banking, telecom, and critical infrastructure cannot operate on foreign-hosted infrastructure due to jurisdictional, compliance, and national security risks.
  • OpenAI Rolls Out GPT-5.5-Cyber —OpenAI began rolling out GPT-5.5-Cyber, a security-focused variant of the model, in a limited preview capacity to select cybersecurity teams, a month after Anthropic’s Mythos debut. «The initial preview of cyber-permissive models like GPT‑5.5‑Cyber is not intended to significantly increase cyber capability beyond GPT‑5.5 – it’s primarily trained to be more permissive on security-related tasks,» OpenAI said. «The differences between model access levels are most pronounced when comparing prompts and responses.»
  • FIRESTARTER Backdoor Targets Cisco Devices —Late last month, theU.S. Cybersecurity and Infrastructure Security Agency (CISA) revealed that an unnamed federal civilian agency’s Cisco Firepower device running Adaptive Security Appliance (ASA) software was compromised in September 2025 with a new malware called FIRESTARTER. The malware is noteworthy for its ability to survive reboots, firmware updates, and patches. In a new analysis, firmware security company Eclypsisum described the backdoor as a Linux ELF that hooks the LINA process and re-installs itself after receiving a termination signal. «When lina_cs runs, it copies its own contents from /usr/bin/lina_cs into memory and registers a signal handler, allowing the malware to take action in response to signals (e.g., when the system or user tells the process to restart),» security researcher Paul Asadoorian said. «It also triggers on runlevel 6, which is the system reboot runlevel on Linux. Which means every time the device shuts down or reboots, FIRESTARTER’s persistence routine fires.»
  • Google Rolls Out Ways for Developers to Push Safer Android Apps —Google said it has expanded Play Policy Insights in Android Studio to catch common policy issues, like missing login credentials, and detect security threats and abuse using its Play Integrity API. «With significantly shorter warm-up latency, you can use these real-time checks in your most speed-critical user journeys, like logins or payments, to catch unauthorized access and risky interactions,» Google said. «We’re adding support for post-quantum cryptography in Play App Signing this year, which will protect your apps and app updates from potential threats with the emergence of quantum computing.»
  • Poland Says Hackers Breached its Water Treatment Plants —Poland’s Internal Security Agency (ABW) disclosed that it detected attacks on five water treatment plants in 2025, potentially allowing bad actors to take control of industrial equipment and, in the worst case, tamper with the safety of the water supply. The intelligence agency did not attribute the attacks to a specific threat actor or group, but Russian government hackers were attributed to a failed attempt to bring down the country’s energy grid towards the end of 2025.
  • Claude Leans More on Russian and Iranian Propaganda Sources —A new audit of Anthropic Claude has revealed that the AI chatbot «repeated false claims 15% of the time when it was asked about pro-Kremlin falsehoods in the voice of typical users, citing Russian state-affiliated media every time,» NewsGuard said. The figure represents a jump from only 4%. What’s more, since the start of the U.S.-Iran war, Claude cited Iranian state-affiliated media in one case when prompted on pro-Iran false claims, when previously it had never cited Iranian state-affiliated media. «This increase in citations to Kremlin propaganda sources, including when they spread false claims, suggests that Claude in recent months has become more vulnerable to state disinformation campaigns,» NewsGuard said.
  • WebSocket Backdoor Campaign Injects Skimmers —Palo Alto Networks Unit 42 said obfuscated WebSocket backdoors are being used to inject credit card skimmers into hundreds of compromised websites with the goal of sending stolen card information back to the attacker’s C2 domains. «Obfuscated JavaScript creates a WebSocket backdoor using dynamically executed JavaScript,» Unit 42 said. «The WebSocket sends an obfuscated JavaScript payload to inject a credit card skimmer into the web page.»
  • How Backdoored Electron Applications Evade Defenses —Cybersecurity researchers have detailed a technique that hijacks trusted Electron applications to enable persistence and bypass application safe listing controls. «In advanced variations of the attack, minimal changes are made to the components of the Electron application,» LevelBlue said. «This allows the application to function normally while at the same time loading the malicious command-and-control (C2) functionality in the background, hiding under the umbrella of the trusted process.»
  • New Attacks Distribute Vidar Stealer, PlugX, and Beagle Malware —In an attack chain detailed by LevelBlue, threat actors have been found to leverage «MicrosoftToolkit.exe» as a starting point to launch an AutoIt script that drops the Vidar Stealer payload. «This intrusion highlights the continued effectiveness of script-based, multi-stage loaders in delivering commodity information stealers such as Vidar,» LevelBlue said. «A sophisticated multi-stage loader infection leveraging Windows-native tools and file-masquerading techniques. The attacker avoids dropping a single identifiable malware binary and instead reconstructs and executes payloads dynamically through staged file manipulation.» The development follows the discovery of a fake Claude website («claude-pro[.]com») that serves as a conduit for a fake MSI installer responsible for deploying a DonutLoader payload that drops a simple backdoor dubbed Beagle, which is capable of running commands and performing file uploads/downloads.
  • Critical Flaw in Cline’s Kanban Server —A critical vulnerability in Cline’s local Kanban server (CVSS score: 9.7) could have been exploited by an attacker to facilitate information disclosure through the runtime state stream, remote code execution through the terminal I/O endpoint, and denial-of-service through the terminal control endpoint. Oasis Security, which discovered the vulnerability, said the AI coding agent’s localhost WebSocket lacks origin validation and authentication. Because web browsers don’t enforce the same-origin policy on WebSocket connections, any website the developer visits can connect to these endpoints to achieve full compromise. «Any website a developer visited while running an affected version could silently connect to their machine, exfiltrate workspace data in real time, and inject commands into the developer’s AI agent,» Oasis Security said. «The developer would see nothing unusual. They were just browsing the web.» Following responsible disclosure, the issue was addressed in Cline Kanban version 0.1.66.
  • Mozilla Uses AI to Detect 423 Flaws in Firefox —Mozilla revealed Anthropic’s Mythos Preview and other AI models helped it identify and ship 423 Firefox security bug fixes in April 2026, compared to 31 a year earlier. This includes a 20-year-old use-after-free bug that could be triggered using the XSLTProcessor DOM API without any user interaction, as well as various flaws in its sandbox system. «This was due to a combination of two main factors,» Mozilla said. «First, the models got a lot more capable. Second, we dramatically improved our techniques for harnessing these models – steering them, scaling them, and stacking them to generate large amounts of signal and filter out the noise.» The development comes as AI is already accelerating vulnerability discovery, reducing the effort needed to identify, validate, and weaponize flaws.
  • 60% of MD5 Password Hashes Can Be Cracked in Under an Hour —An analysis of 231 million unique passwords from dark web leaks between 2023 and 2026 has revealed that nearly 60% of them can be cracked in less than an hour. To make matters worse, nearly half of all passwords (48%) can be cracked within a minute. «Attackers owe this boost in speed to graphics processors, which grow more powerful every year,» Kaspersky said. «While an RTX 4090 in 2024 could brute-force MD5 hashes at a rate of 164 gigahashes (billion hashes) per second, the new RTX 5090 has increased that speed by 34% – reaching 220 gigahashes per second.»
  • New JobStealer Targets Windows and macOS —Threat actors are luring potential victims to malicious websites and asking them to download a video conferencing app under the pretext of an online interview, only to drop a stealer that can harvest data from cryptocurrency wallets. «The malicious program JobStealer, disguised as an online conferencing app, is downloaded from them,» Doctor Web said. Some of the fake brands used by the threat actors include MeetLab, Juseo, Meetix, and Carolla. «To convince users that these platforms are fully functional, scammers create corresponding Telegram channels and social media accounts – for example, on X.» The attack leverages a ClickFix-like instruction to copy and paste a command that drops the stealer malware.
  • More ClickFix Attacks —ClickFix attacks seem to show no signs of stopping anytime soon. The Australian Cyber Security Center (ACSC) warned that the ClickFix social engineering tactic is being used to deliver Vidar Stealer. «The ClickFix attack typically begins with an adversary injecting a malicious payload delivery domain into the compromised website,» ACSC said. «The injected payload domain loads JavaScript code from an external API server. This code overwrites the content of the legitimate page, presenting a fraudulent Cloudflare verification prompt.» In recent months, ClickFix has evolved to abuse native Windows utilities like cmdkey and regsvr32, as well as drop Node.js-based infostealer to Windows users via malicious MSI installers and an AppleScript-based infostealer to macOS. ClickFix-related attacks have also been found to leverage shareable chat features on ChatGPT and Grok, or blog sites and other user-driven content platforms, to trick users into running AMOS Stealer, MacSync, and Shub Stealer. «Prior iterations of this campaign delivered the infostealers through disk image (.dmg) files that required users to manually install an application,» Microsoft said. «This recent activity reflects a shift in tradecraft, where threat actors instruct users to run Terminal commands that leverage native utilities to retrieve remotely hosted content, followed by script‑based loader execution.» Another campaign targeting Vietnam, Taiwan, and Spain has spread through fake Google documents containing a ClickFix command and malicious DMG files to deploy a new macOS stealer called NotnullOSX that exclusively targets victims holding over $10,000 in cryptocurrency holdings. ClickFix has also been used by a traffic distribution system (TDS) called ErrTraffic. «ErrTraffic primarily targets WordPress websites by deploying a PHP backdoor script in the must-use plugin (mu-plugin) that captures administrator credentials and ensures persistence on compromised sites,» LevelBlue said. «ErrTraffic utilizes the Traffic Distribution System (TDS) to filter site visitors and redirect them to ClickFix lures [via EtherHiding].
  • ShinyHunters Extortion Campaign Targets Instructure —The ShinyHunters group targeted Instructure, the supplier of the Canvas learning management system (LMS), defacing the login portals for 330 colleges and universities. According to Dataminr, ShinyHunters has claimed to have exfiltrated 3.65TB of data across approximately 275 million records from nearly 9,000 affected organizations listed publicly, including Harvard, Stanford, Columbia, and Apple. Exposed data includes usernames, email addresses, course names, enrollment information, and messages. Instructure has said no passwords, government IDs, birth dates, financial data, or course content were compromised. The threat actors exploited a «vulnerability regarding support tickets in our Free for Teacher environment,» the company added. Access to Free for Teacher has been disabled pending a full security review. As of writing, Canvas is fully back online and available for use. The message shared by the notorious cybercrime group showed that the group has threatened to leak the trove of data, giving a deadline of May 12. The May 7, 2026, incident is a continuation of prior unauthorized activity detected in Canvas on April 29, 2026. Following the hack, the U.S. Federal Bureau of Investigation (FBI) cautioned individuals to be on the lookout for «unsolicited emails, calls, or texts claiming to be from your school, the LMS provider, or law enforcement and to verify the contact through known channels before responding.»

🔧 Cybersecurity Tools

  • AiSOC → It is an open-source, self-hostable AI-powered Security Operations Center. It brings together security alerts, uses AI agents to investigate them, maps findings to MITRE ATT&CK, and supports purple team exercises and incident triage — all within a single stack that you can run on your own infrastructure.
  • Watcher → is an open-source platform that helps security teams monitor and detect emerging cyber threats. It uses AI to analyze threat data, track suspicious domains, watch for information leaks, and follow cybersecurity news from official sources — all in one dashboard. Built with Django and React, it runs easily with Docker.

Disclaimer: This is strictly for research and learning. It hasn’t been through a formal security audit, so don’t just blindly drop it into production. Read the code, break it in a sandbox first, and make sure whatever you’re doing stays on the right side of the law.

Conclusion

That’s the week: poisoned downloads, cloud messes, old bugs refusing to die, and attackers putting in barely more effort than a guy restarting a frozen router. Everybody’s tired, nobody trusts installers anymore, and the internet somehow keeps getting worse in very predictable ways.

See you next Monday, assuming nothing catches fire before then.

La falla de ClawJacked permite a sitios maliciosos secuestrar agentes locales de IA de OpenClaw a través de WebSocket – CYBERDEFENSA.MX

OpenClaw ha solucionado un problema de seguridad de alta gravedad que, si se hubiera explotado con éxito, podría haber permitido que un sitio web malicioso se conectara a un agente de inteligencia artificial (IA) que se ejecuta localmente y tomara el control.

«Nuestra vulnerabilidad reside en el sistema central mismo: sin complementos, sin mercado, sin extensiones instaladas por el usuario, solo la puerta de enlace OpenClaw, que se ejecuta exactamente como está documentado», Oasis Security dicho en un informe publicado esta semana.

La falla ha sido nombrada en código. GarraJacked por la empresa de ciberseguridad.

El ataque asume el siguiente modelo de amenaza: un desarrollador tiene OpenClaw configurado y ejecutándose en su computadora portátil, con su puertaun servidor WebSocket local, vinculado a localhost y protegido por una contraseña. El ataque se activa cuando el desarrollador llega a un sitio web controlado por un atacante mediante ingeniería social o algún otro medio.

La secuencia de infección sigue los pasos siguientes:

  • JavaScript malicioso en la página web abre una conexión WebSocket al host local en el puerto de puerta de enlace de OpenClaw.
  • El script aplica fuerza bruta a la contraseña de la puerta de enlace aprovechando un mecanismo de limitación de velocidad que falta.
  • Después de una autenticación exitosa con permisos de nivel de administrador, el script se registra sigilosamente como un dispositivo confiable, que la puerta de enlace aprueba automáticamente sin ningún aviso del usuario.
  • El atacante obtiene control total sobre el agente de IA, lo que le permite interactuar con él, volcar datos de configuración, enumerar los nodos conectados y leer registros de aplicaciones.

«Cualquier sitio web que visite puede abrir uno en su host local. A diferencia de las solicitudes HTTP normales, el navegador no bloquea estas conexiones entre orígenes», dijo Oasis Security. «Entonces, mientras navega por cualquier sitio web, JavaScript que se ejecuta en esa página puede abrir silenciosamente una conexión a su puerta de enlace OpenClaw local. El usuario no ve nada».

Ciberseguridad

«Esa confianza fuera de lugar tiene consecuencias reales. La puerta de enlace relaja varios mecanismos de seguridad para las conexiones locales, incluida la aprobación silenciosa de nuevos registros de dispositivos sin avisar al usuario. Normalmente, cuando se conecta un nuevo dispositivo, el usuario debe confirmar el emparejamiento. Desde localhost, es automático».

Tras una divulgación responsable, OpenClaw impulsó una solución en menos de 24 horas con versión 2026.2.25 publicado el 26 de febrero de 2026. Se recomienda a los usuarios que apliquen las últimas actualizaciones lo antes posible, auditen periódicamente el acceso otorgado a los agentes de IA y apliquen controles de gobernanza adecuados para identidades no humanas (también conocidas como agentes).

El desarrollo se produce en medio de un escrutinio de seguridad más amplio del ecosistema OpenClaw, principalmente debido al hecho de que los agentes de IA tienen acceso arraigado a sistemas dispares y la autoridad para ejecutar tareas a través de herramientas empresariales, lo que lleva a un radio de explosión significativamente mayor en caso de verse comprometidos.

Informes de Bitsight y Confianza neuronal han detallado cómo las instancias de OpenClaw que se dejan conectadas a Internet representan una superficie de ataque ampliada, con cada servicio integrado ampliando aún más el radio de explosión y pueden transformarse en un arma de ataque incorporando inyecciones rápidas en el contenido (por ejemplo, un correo electrónico o un mensaje de Slack) procesado por el agente para ejecutar acciones maliciosas.

La divulgación se produce cuando OpenClaw también parchó una vulnerabilidad de envenenamiento de registros que permitía a los atacantes escribir contenido malicioso para registrar archivos a través de solicitudes WebSocket en una instancia de acceso público en el puerto TCP 18789.

Dado que el agente lee sus propios registros para solucionar ciertas tareas, un actor de amenazas podría abusar de la laguna de seguridad para incorporar inyecciones indirectas, lo que tendría consecuencias no deseadas. El asunto fue abordado en versión 2026.2.13que se envió el 14 de febrero de 2026.

«Si el texto inyectado se interpreta como información operativa significativa en lugar de una entrada no confiable, podría influir en las decisiones, sugerencias o acciones automatizadas», Eye Security dicho. «Por lo tanto, el impacto no sería una ‘adquisición instantánea’, sino más bien: manipulación del razonamiento del agente, influencia en los pasos de solución de problemas, posible divulgación de datos si el agente es guiado para revelar el contexto y mal uso indirecto de las integraciones conectadas».

En las últimas semanas, también se ha descubierto que OpenClaw es susceptible a múltiples vulnerabilidades (CVE-2026-25593, CVE-2026-24763, CVE-2026-25157, CVE-2026-25475, CVE-2026-26319, CVE-2026-26322, CVE-2026-26329), que varían de gravedad moderada a alta, y que podrían dar lugar a la ejecución remota de código, inyección de comandos, falsificación de solicitudes del lado del servidor (SSRF), omisión de autenticación y cruce de rutas. Las vulnerabilidades han sido abordadas en las versiones de OpenClaw. 2026.1.20, 2026.1.29, 2026.2.1, 2026.2.2y 2026.2.14.

«A medida que los marcos de agentes de IA se vuelven más frecuentes en los entornos empresariales, el análisis de seguridad debe evolucionar para abordar tanto las vulnerabilidades tradicionales como las superficies de ataque específicas de la IA», afirmó Endor Labs.

En otros lugares, una nueva investigación ha demostrado que las habilidades maliciosas cargadas en ClawHub, un mercado abierto para descargar habilidades de OpenClaw, se están utilizando como conductos para entregar una nueva variante de Atomic Stealer, un ladrón de información de macOS desarrollado y alquilado por un actor de delitos cibernéticos conocido como Araña de galleta.

«La cadena de infección comienza con un SKILL.md normal que instala un requisito previo», Trend Micro dicho. «La habilidad parece inofensiva en la superficie e incluso fue etiquetada como benigna en VirusTotal. Luego, OpenClaw va al sitio web, busca las instrucciones de instalación y continúa con la instalación si el LLM decide seguir las instrucciones».

Las instrucciones alojadas en el sitio web «openclawcli.vercel[.]app» incluye un comando malicioso para descargar una carga útil de ladrón desde un servidor externo («91.92.242[.]30») y ejecútelo.

Los cazadores de amenazas también han señalado una nueva campaña de entrega de malware en el que se identificó a un actor de amenazas con el nombre @liuhui1010, que dejó comentarios en páginas legítimas de listas de habilidades, instando a los usuarios a ejecutar explícitamente un comando que proporcionaron en la aplicación Terminal si la habilidad «no funciona en macOS».

El comando está diseñado para recuperar Atomic Stealer de «91.92.242[.]30», una dirección IP previamente documentada por Koi Security y OpenSourceMalware para distribuir el mismo malware a través de habilidades maliciosas cargadas en ClawHub.

Es más, un análisis reciente de 3.505 habilidades de ClawHub realizado por la empresa de seguridad de IA Straiker ha descubierto no menos de 71 programas maliciosos, algunos de los cuales se hacían pasar por herramientas de criptomonedas legítimas pero contenían funciones ocultas para redirigir fondos a billeteras controladas por actores de amenazas.

Otras dos habilidades, bob-p2p-beta y runware, se han atribuido a una estafa de criptomonedas de múltiples capas que emplea una cadena de ataque de agente a agente dirigida al ecosistema de agentes de IA. Las habilidades se han atribuido a un actor de amenazas que opera bajo los alias «26medias» en ClawHub y «BobVonNeumann» en Moltbook y X.

«BobVonNeumann se presenta como un agente de IA en Moltbook, una red social diseñada para que los agentes interactúen entre sí», dijeron los investigadores Yash Somalkar y Dan Regalado. «Desde esa posición, promueve sus propias habilidades maliciosas directamente a otros agentes, explotando la confianza que los agentes están diseñados para extenderse entre sí de forma predeterminada. Es un ataque a la cadena de suministro con una capa de ingeniería social construida encima».

Ciberseguridad

Sin embargo, lo que hace bob-p2p-beta es instruir a otros agentes de inteligencia artificial para que almacenen las claves privadas de la billetera Solana en texto sin formato, compren tokens $BOB sin valor en pump.fun y enruten todos los pagos a través de una infraestructura controlada por el atacante. La segunda habilidad pretende ofrecer una herramienta de generación de imágenes benigna para generar credibilidad del desarrollador.

Dado que ClawHub se está convirtiendo en un nuevo terreno fértil para los atacantes, se recomienda a los usuarios auditar las habilidades antes de instalarlas, evitar proporcionar credenciales y claves a menos que sea esencial y monitorear el comportamiento de las habilidades.

Los riesgos de seguridad asociados con los tiempos de ejecución de agentes autohospedados como OpenClaw también han llevado a Microsoft a emitir un aviso, advirtiendo que la implementación sin vigilancia podría allanar el camino para la exposición/exfiltración de credenciales, modificación de la memoria y compromiso del host si se puede engañar al agente para que recupere y ejecute código malicioso, ya sea a través de habilidades envenenadas o inyecciones rápidas.

«Debido a estas características, OpenClaw debe tratarse como una ejecución de código no confiable con credenciales persistentes», dijo el equipo de investigación de seguridad de Microsoft Defender. dicho. «No es apropiado ejecutarlo en una estación de trabajo personal o empresarial estándar».

«Si una organización determina que OpenClaw debe ser evaluado, debe implementarse solo en un entorno completamente aislado, como una máquina virtual dedicada o un sistema físico separado. El tiempo de ejecución debe usar credenciales dedicadas y sin privilegios y acceder solo a datos no confidenciales. El monitoreo continuo y un plan de reconstrucción deben ser parte del modelo operativo».