{"id":10863,"date":"2026-02-22T10:04:33","date_gmt":"2026-02-22T10:04:33","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/02\/22\/multiple-hacking-groups-exploit-openclaw-instances-to-steal-api-key-and-deploy-malware\/"},"modified":"2026-02-22T10:04:33","modified_gmt":"2026-02-22T10:04:33","slug":"multiple-hacking-groups-exploit-openclaw-instances-to-steal-api-key-and-deploy-malware","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/02\/22\/multiple-hacking-groups-exploit-openclaw-instances-to-steal-api-key-and-deploy-malware\/","title":{"rendered":"Multiple Hacking Groups Exploit OpenClaw Instances to Steal API key and Deploy Malware"},"content":{"rendered":"<p>    Multiple Hacking Groups Exploit OpenClaw Instances to Steal API key and Deploy Malware<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A widespread exploitation of\u00a0<a href=\"https:\/\/cybersecuritynews.com\/clawdbot-chats-exposed\/\" target=\"_blank\" rel=\"noreferrer noopener\">OpenClaw, formerly known as\u00a0MoltBot and\u00a0ClawdBot<\/a>, by multiple hacking groups to deploy malicious payloads.<\/p>\n<p>OpenClaw, an open-source autonomous <a href=\"https:\/\/cybersecuritynews.com\/openclaw-and-openai\/\" target=\"_blank\" rel=\"noreferrer noopener\">AI framework developed by\u00a0Peter Steinberger, now at OpenAI<\/a>, has become a high-severity target following its viral adoption in late January 2026.<\/p>\n<p>Its architecture grants significant system privileges, persistent memory access, and integration with sensitive services, making it a prime candidate for credential theft and data exfiltration.<\/p>\n<p>Within 72 hours of broad deployment, threat actors began exploiting several serious vulnerabilities.<\/p>\n<p>Including the high-risk\u00a0<a href=\"https:\/\/cybersecuritynews.com\/openclaw-control-panels-exposed\/\" target=\"_blank\" rel=\"noreferrer noopener\">Remote Code Execution flaw (CVE-2026-25253)<\/a>, supply chain poisoning, and credential harvesting through exposed administrative interfaces.<\/p>\n<p>Flare analysts have observed over\u00a030,000 compromised OpenClaw instances used to steal API keys, intercept messages, and distribute info-<a href=\"https:\/\/cybersecuritynews.com\/malicious-go-module-package-as-fast-ssh-brute-forcer\/\" target=\"_blank\" rel=\"noreferrer noopener\">stealing malware via Telegram<\/a> and other malicious communication channels.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-clawhavoc-campaign-supply-chain-mass-deployment\"><strong>ClawHavoc Campaign: Supply Chain Mass Deployment<\/strong><\/h2>\n<p>One of the earliest and most <a href=\"https:\/\/cybersecuritynews.com\/clawhavoc-poisoned-openclaws-clawhub\/\" target=\"_blank\" rel=\"noreferrer noopener\">damaging campaigns, dubbed\u00a0\u201cClawHavoc,\u201d<\/a>\u00a0was detected on\u00a0January 29, 2026.<\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiUUskifNibhRcRN6b_6bGL-A1wePZeu0BargovXMO082yJ2rpehD0WIcA0oAvQHnTYdfYra1sJgnDifrvPMnemweNIdN83C2MK9wVhW26dxqxnRO4kDNiEhUlUAsRWCckzmZr7s2i717NZUkJGAczCLF-sy24qnNWYQQQq1B3rnW1drLE2LN08wgAwUoY\/s1600\/Screenshot%25202026-02-21%2520162937%2520%25281%2529.webp?ssl=1\" alt=\"\u201cHightower6eu\u201d was used for mass automated deployments(source : Flare)\"><figcaption class=\"wp-element-caption\">\u201c<em>Hightower6eu\u201d<\/em> was used for mass automated deployments(source : Flare)<\/figcaption><\/figure>\n<p>This supply chain attack disguised <a href=\"https:\/\/cybersecuritynews.com\/atomic-macos-stealer-comes-with-new-backdoor\/\" target=\"_blank\" rel=\"noreferrer noopener\">malicious payloads like\u00a0Atomic Stealer (for macOS)<\/a>\u00a0and\u00a0keyloggers (for Windows)\u00a0as legitimate crypto tools.<\/p>\n<p>Users installing from supposed \u201csetup\u201d scripts unknowingly downloaded stealer malware capable of full-service compromise, enabling attackers to extract persistent memory data and conduct lateral movement across enterprise systems.<\/p>\n<p>By early February, a second campaign, Automated <a href=\"https:\/\/cybersecuritynews.com\/openclaw-supply-chain-attacks\/\" target=\"_blank\" rel=\"noreferrer noopener\">Skill Poisoning Through ClawHub<\/a>, emerged through the OpenClaw community marketplace.<\/p>\n<p>Due to the platform\u2019s open publishing model and lack of code review, attackers uploaded backdoored \u201cskills\u201d from seemingly trustworthy GitHub accounts such as\u00a0Hightower6eu.<\/p>\n<p>These malicious updates executed remote shell commands, allowing attackers to <a href=\"https:\/\/cybersecuritynews.com\/salesloft-drift-hacked\/\" target=\"_blank\" rel=\"noreferrer noopener\">exfiltrate\u00a0OAuth tokens<\/a>, passwords, and API keys\u00a0in real time.<\/p>\n<p>A Shodan scan on February 18, 2026, found 312,000+ OpenClaw instances running on default port 18789, many with no authentication and open to the internet.<\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgBkWL814HZJTxWDHnveud7xWzsfsg95iSGQy642CIdJNIuPLbOQ-9eWfcRquevb9jSK37bPA9dn7X3vQ0SCR86x3ytZ2jpLR8PJ1Thv0uJI1IMicXIn3Ma6P5byP_Z7BerI592kXsQ3Tqqwn3MbSOVgSkrAUzooZmV4N4y6vrXSvYCzb1DU86ZZZRDft0\/s1600\/Screenshot%25202026-02-21%2520162953%2520%25281%2529.webp?ssl=1\" alt=\"\nShodan search for default port 18789 on February 18, 2025( source : Flare)\"><figcaption class=\"wp-element-caption\">Shodan search for default port 18789 on February 18, 2025( source: Flare)<\/figcaption><\/figure>\n<p>Meanwhile,\u00a0exposed administrative interfaces\u00a0are worsening the crisis. <a href=\"https:\/\/cybersecuritynews.com\/lazarus-recruitment-live-on-camera\/\" target=\"_blank\" rel=\"noreferrer noopener\">Honeypot deployments<\/a> have recorded exploitation attempts within minutes of exposure.<\/p>\n<p>The OpenClaw incidents underscore a critical turning point in the security of\u00a0autonomous AI agents. Organized threat groups have adapted rapidly, weaponizing an ecosystem that prioritized capability over cybersecurity.<\/p>\n<p>As OpenAI absorbs OpenClaw\u2019s developer, experts warn that these issues highlight the urgent need for\u00a0security-by-design\u00a0approaches in future AI frameworks.<\/p>\n<p><span style=\"box-sizing: border-box; margin: 0px; padding: 0px;\">A <a href=\"https:\/\/flare.io\/learn\/resources\/blog\/widespread-openclaw-exploitation\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Flare advisory recommends<\/a> that companies using or testing autonomous assistants\u00a0secure<\/span> API credentials and isolate AI workloads.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/hacking-groups-exploit-openclaw\/\">Multiple Hacking Groups Exploit OpenClaw Instances to Steal API key and Deploy Malware<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Abinaya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/hacking-groups-exploit-openclaw\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Multiple Hacking Groups Exploit OpenClaw Instances to Steal API key and Deploy Malware A widespread exploitation of\u00a0OpenClaw, formerly known as\u00a0MoltBot and\u00a0ClawdBot, by multiple hacking groups to deploy malicious payloads. OpenClaw, an open-source autonomous AI framework developed by\u00a0Peter Steinberger, now at OpenAI, has become a high-severity target following its viral adoption in late January 2026. Its [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63],"tags":[130],"class_list":["post-10863","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/10863"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=10863"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/10863\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=10863"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=10863"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=10863"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}