CampaignReported removedCoverage: Partly coveredPrimary source

Skills distributing an Atomic macOS Stealer variant

Reported by Trend Micro on . Names, numbers, and dates are as the sources state them.

What it did

Trend Micro identified 39 skills that told the agent to install a fake OpenClawCLI from a lookalike website, which served an obfuscated command that downloaded an AMOS variant. The stealer showed a fake password prompt and collected keychains, browser data, documents and wallet data. Trend Micro observed that a more capable model refused the install while another kept asking the user to run it.

Techniques

  • Fake prerequisite
  • Lookalike website
  • Encoded command
  • Infostealer

Status, as stated by the source

Trend Micro says the 39 skills had all been taken down at the time of writing, while their code remained in ClawHub’s GitHub repository and on other skill sites.

We do not check the registry ourselves. “Unknown” means no source we found says the skill was removed.

Would Ironheights flag this pattern?

Partly covered

Only the link to the lookalike website is flagged (IH-NET-001). The command lived on the website.

Rules that fire on a harmless, synthetic copy of the reported pattern. We did not scan the original malware, and a rule firing on the pattern is not a promise about every variant.

Sources

  1. Malicious OpenClaw Skills Used to Distribute Atomic macOS Stealer(opens in a new tab)Trend Micro · primary

Sources are the only outbound links on this page. We never link to the skills themselves or publish their payloads.

Rules that look at neighbouring patterns. They are listed for reading, not as coverage of this entry.