Threat reportMalwareTL-2026-0480

OpenClaw Hologram Rust Infostealer — Multi-Wave Campaign Abusing Hookdeck Webhook Gateway as C2 Relay

highACTIVE

OpenClaw Hologram Rust Infostealer (TL-2026-0480), also tracked as Hologram, is a high-severity malware campaign, first published 2026-05-07. It has no confirmed attribution, affects Microsoft Windows, maps to 25 MITRE ATT&CK techniques (T1027.001, T1027.013, T1041), and is covered by 9 detection rules and 30 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
25MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
30Indicators of compromise

Key facts for TL-2026-0480

Threat ID
TL-2026-0480
Also known as
Hologram, Pathfinder (Wave 3), OpenClaw fake-installer campaign
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution confidence
NONE
Motivation
FINANCIAL
Target sectors
consumer, cryptocurrency, financial, technology
Target regions
Global, North America, Europe, South America
Detection rules
9
Indicators of compromise
30

Malware and tooling in OpenClaw Hologram Rust Infostealer

Malware and tooling: Hologram, Pathfinder, Hookdeck webhook gateway, clroxide (Rust crate), memexec (Rust crate), stealth_packer

How OpenClaw Hologram Rust Infostealer works

Hologram is a previously undocumented six-binary Rust modular implant framework distributed via fake OpenClaw installers since at least February 2026 and disclosed by Netskope Threat Labs on 2026-05-07. The framework targets credentials from 250+ cryptocurrency wallet and password-manager browser extensions and debuts two notable tradecraft elements: weaponization of the Hookdeck webhook gateway as a victim-telemetry C2 relay, and the first criminal use of the clroxide Rust crate for process injection. A third campaign wave (Pathfinder) rotated infrastructure mid-analysis, demonstrating active development.

Hologram is a previously undocumented, modular Rust-based information-stealing implant framework distributed as fake "OpenClaw" installers since at least February 2026. Documented by Netskope Threat Labs on May 7, 2026, the campaign couples a deliberately bloated ~130MB Rust dropper with a six-binary stage-2 framework that targets credentials from over 250 cryptocurrency wallet and password-manager browser extensions, plus a separately staged Ledger Live module. Hologram introduces two tradecraft elements not previously observed in commodity crimeware: weaponization of Hookdeck (a legitimate webhook gateway service) as a victim-telemetry C2 relay, and the first observed criminal use of the clroxide Rust crate to perform CLR-based process injection.

Victims are funneled to the typosquat domain openclaw-installer.com (registered 2026-03-09 via an Alibaba-affiliated Chinese registrar and fronted by Cloudflare), which serves a 7-Zip archive named OpenClaw_x64.7z, distributed in part through the GitHub typosquat organization openclaw-install/openclaw-installer (created via throwaway account bgodimpulse7) impersonating the legitimate openclaw/openclaw repository. The archive contains OpenClaw_x64.exe, a deliberately bloated ~130MB Rust binary built with stable-x86_64-pc-windows-msvc whose Cargo build path C:\Users\root\.cargo\ leaks the operator development environment. The PE manifest identifies the implant by its internal name, Hologram, with a description ("Decoy entity generator for tactical misdirection.") and version v1.7.16 — evidence of structured internal development. The 130MB pad simultaneously defeats AV file-size scanning heuristics and exceeds the upload cap of many automated sandbox services.

Hologram performs aggressive layered anti-analysis before executing its second stage. Checks include VirtualBox BIOS string queries, sandbox-associated DLL enumeration, VM-prefixed MAC address detection, blacklisted username comparison, and a multi-attribute hardware fingerprint score over GPU, CPU core count, RAM, disk size, running process count, and screen resolution. The implant additionally requires real user activity via a mouse-movement gate, defeating sandboxes that do not simulate input. In wave 3 (Pathfinder), the driver-list enumeration was replaced by a BIOS string query, indicating active operator iteration on detection-evasion logic.

Stage 1 is a Base64+XOR (key 44) obfuscated PowerShell loader. It disables Microsoft Defender (kill, six exclusion paths covering C:\Users\Public\ and the redundant copy locations, cloud blocking off, behavior monitoring off), splits cmdlet names into string fragments to evade signature-based AMSI rules, and opens inbound Windows Firewall rules on TCP/57001, 57002, and 56001. The stage-2 framework is dropped into C:\Users\Public\ with redundant copies under the user''s Documents, Music, Pictures, and Videos folders to defeat single-path remediation.

Stage 2 is a six-binary modular framework — svc_service.exe, virtnetwork.exe, audioeq.exe, OneSync.exe, WinHealhCare.exe, and onedrive_sync.exe — packed with a custom internal packer ("stealth_packer") that shares a build environment with the wave-1 Huntress-documented February 2026 samples, anchoring continuity of operator identity across waves. Five binaries are 64-bit Rust; onedrive_sync.exe is the lone 32-bit Rust binary. The newest core binaries (virtnetwork.exe, audioeq.exe) were compiled 2026-04-27 — one week pre-publication — confirming active development. Persistence is established with a malicious OneDriveSync.lnk in the system Startup folder, supplemented by a WinLogon Userinit registry hijack, a privileged scheduled task, and COM hijacking. Process injection leverages the clroxide Rust crate (first criminal use) and reflective PE loading via memexec, with thread injection performed via direct NT system-call stubs to bypass user-mode EDR API hooks.

The C2 architecture pairs a primary server (assessed as a hijacked Brazilian law-firm domain) with a DigitalOcean-hosted secondary server. Stage-2 binaries are pulled from an attacker-controlled Azure DevOps organization (sagonbretzpr). Configuration data is retrieved via dead-drop resolvers on Telegram (channel b8bz11) and snippet.host. Most distinctively, victim telemetry — username, public IP, timestamp — is exfiltrated through Hookdeck''s hkdk.events relay (URL hkdk.events/djbk1i9hp0sqoh), abusing a legitimate webhook gateway to obscure backend infrastructure and survive blocklist takedowns. Hologram targets credentials from 250+ cryptocurrency wallet and password-manager browser extensions; Ledger Live is fetched as a separate module from a distinct URL. Wave 3 (Pathfinder), active during Netskope''s analysis, rotated primary and secondary C2, the Telegram dead-drop, the campaign tag, and added two stage-2 binaries — operator infrastructure resilience exceeds typical commodity stealer playbooks.

MITRE ATT&CK techniques used in TL-2026-0480

Defense Evasion

T1027.001 Obfuscated Files or Information: Binary Padding; T1027.013 Obfuscated Files or Information: Encrypted/Encoded File; T1497.001 Virtualization/Sandbox Evasion: System Checks; T1497.002 Virtualization/Sandbox Evasion: User Activity Based Checks; T1620 Reflective Code Loading

Exfiltration

T1041 Exfiltration Over C2 Channel

Persistence

T1053.005 Scheduled Task/Job: Scheduled Task; T1546.015 Event Triggered Execution: Component Object Model Hijacking; T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder; T1547.004 Boot or Logon Autostart Execution: Winlogon Helper DLL

Privilege Escalation

T1055 Process Injection

Execution

T1059.001 Command and Scripting Interpreter: PowerShell; T1106 Native API; T1204.002 User Execution: Malicious File

Command and Control

T1071.001 Application Layer Protocol: Web Protocols; T1102.001 Web Service: Dead Drop Resolver; T1102.002 Web Service: Bidirectional Communication

Collection

T1119 Automated Collection

Initial Access

T1189 Drive-by Compromise

Credential Access

T1555.003 Credentials from Password Stores: Credentials from Web Browsers; T1555.005 Credentials from Password Stores: Password Managers

Resource Development

T1583 Acquire Infrastructure; T1608 Stage Capabilities

defense-impairment

T1685 Disable or Modify Tools; T1686 Disable or Modify System Firewall

Affected products and versions in OpenClaw Hologram Rust Infostealer

  • Microsoft — Windows
    Vulnerable versions: Windows 10 x64; Windows 11 x64; Windows Server 2019/2022 (x64 and x86 user contexts)
  • Multiple — Cryptocurrency Wallet Browser Extensions
    Vulnerable versions: 250+ targeted extensions including MetaMask, Phantom, Trust Wallet, Coinbase Wallet, Brave Wallet, Exodus Web3
  • Multiple — Password Manager Browser Extensions
    Vulnerable versions: LastPass, Bitwarden, 1Password, Dashlane, KeePass-XC, Keeper, NordPass browser extensions
  • Ledger — Ledger Live
    Vulnerable versions: all current Windows versions (separately staged module fetched from distinct URL)

Remediation for OpenClaw Hologram Rust Infostealer

Immediate actions

  • Block openclaw-installer.com and hkdk.events at DNS/web proxy
  • Quarantine Windows endpoints with svc_service.exe, virtnetwork.exe, audioeq.exe, OneSync.exe, WinHealhCare.exe, or onedrive_sync.exe in C:\Users\Public\ or the redundant copy folders
  • Hunt for OneDriveSync.lnk in Startup folders and remove
  • Revoke browser-stored credentials, password-manager vault items, and crypto wallet seed phrases for any infected user
  • Audit Windows Firewall for inbound rules on TCP/57001, 57002, 56001 and remove
  • Reset password-manager master passwords for affected users (assume vault export)
  • Inspect WinLogon Userinit registry value and revert any modifications

Workarounds

  • If Defender tamper protection cannot be enforced, alert on Defender service stop events (Event ID 7036) and Set-MpPreference -ExclusionPath additions
  • If browser-extension allowlisting is unavailable, monitor and alert on outbound TLS to known wallet-extension update URLs from unexpected processes
  • Block 7-Zip archives sourced from non-allowlisted GitHub release URLs at the web gateway

Longer-term hardening

  • Deploy EDR with kernel-mode telemetry; user-mode-only API hooking is defeated by Hologram''s direct NT syscall thread injection
  • Enforce Microsoft Defender tamper protection so service-stop and exclusion-add operations fail
  • Block GitHub typosquat orgs at source-control egress; require allowlisted org pulls for developer endpoints
  • Restrict execution from C:\Users\Public\ via WDAC or AppLocker policy
  • Enforce browser-extension allowlisting via Chrome enterprise policy ExtensionInstallAllowlist
  • Detect outbound connections to webhook-gateway domains (hkdk.events, *.webhook.site, ngrok-*) from non-developer endpoints
  • Hunt for COM hijack indicators (suspicious user-writable CLSID InprocServer32 entries) on a recurring basis

Timeline of OpenClaw Hologram Rust Infostealer

  • Wave 1 of OpenClaw fake-installer campaign documented by Huntress; payloads were Vidar and PureLogs with Telegram dead-drop C2 resolution. Same stealth_packer build environment later used in Hologram.
  • Typosquat distribution domain openclaw-installer.com registered through an Alibaba-affiliated Chinese registrar and fronted by Cloudflare.
  • Newest core stage-2 modules virtnetwork.exe and audioeq.exe compiled (Rust stable-x86_64-pc-windows-msvc) — one week before public disclosure, confirming active development.
  • Wave 3 (Pathfinder) infrastructure rotation observed by Netskope mid-analysis: new primary/secondary C2, new Telegram dead-drop, new campaign tag, two additional stage-2 binaries; driver-list anti-VM check replaced with BIOS string query.
  • Campaign assessed ACTIVE: Pathfinder wave running with rotated infrastructure at time of publication; further infrastructure churn expected.
  • Threadlinqs Intelligence ingested TL-2026-0480 with full IOC, MITRE, and detection coverage.
  • Netskope Threat Labs publishes 'OpenClaw's Hologram: Fake Installer Ships Rust Infostealer' — first public documentation of the Hologram framework, Hookdeck C2 abuse, and clroxide criminal use.
  • As of 2026-05-29, the OpenClaw Hologram/Pathfinder Rust infostealer remains active: Netskope (2026-05-07) and SOC Prime (2026-05-11) report frequent infrastructure rotation across domains, Telegram, and Hookdeck with no takedown or arrest, and the broader OpenClaw lure ecosystem is expanding. Built for blocklist resilience and under active development (binaries compiled 2026-04-27), it is a live, unattributed financial-crimeware threat.

Sources cited for OpenClaw Hologram Rust Infostealer

Detection coverage for TL-2026-0480

As of 2026-05-07, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0480 across Splunk SPL, Microsoft KQL and Sigma, covering 30 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
30 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats