# OpenClaw Hologram Rust Infostealer — Multi-Wave Campaign Abusing Hookdeck Webhook Gateway as C2 Relay

> Hologram is a previously undocumented six-binary Rust modular implant framework distributed via fake OpenClaw installers since at least February 2026 and disclosed by Netskope Threat Labs on 2026-05-07. The framework targets credentials from 250+ cryptocurrency wallet and password-manager browser extensions and debuts two notable tradecraft elements: weaponization of the Hookdeck webhook gateway as a victim-telemetry C2 relay, and the first criminal use of the clroxide Rust crate for process injection. A third campaign wave (Pathfinder) rotated infrastructure mid-analysis, demonstrating active development.

- **Published:** 2026-05-07T12:00:00Z
- **Last reviewed:** 2026-05-07T12:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0480
- **ID:** TL-2026-0480
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 30 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Hologram is a previously undocumented, modular Rust-based information-stealing implant framework distributed as fake "OpenClaw" installers since at least February 2026. Documented by Netskope Threat Labs on May 7, 2026, the campaign couples a deliberately bloated ~130MB Rust dropper with a six-binary stage-2 framework that targets credentials from over 250 cryptocurrency wallet and password-manager browser extensions, plus a separately staged Ledger Live module. Hologram introduces two tradecraft elements not previously observed in commodity crimeware: weaponization of Hookdeck (a legitimate webhook gateway service) as a victim-telemetry C2 relay, and the first observed criminal use of the clroxide Rust crate to perform CLR-based process injection.

Victims are funneled to the typosquat domain openclaw-installer.com (registered 2026-03-09 via an Alibaba-affiliated Chinese registrar and fronted by Cloudflare), which serves a 7-Zip archive named OpenClaw_x64.7z, distributed in part through the GitHub typosquat organization openclaw-install/openclaw-installer (created via throwaway account bgodimpulse7) impersonating the legitimate openclaw/openclaw repository. The archive contains OpenClaw_x64.exe, a deliberately bloated ~130MB Rust binary built with stable-x86_64-pc-windows-msvc whose Cargo build path C:\Users\root\.cargo\ leaks the operator development environment. The PE manifest identifies the implant by its internal name, Hologram, with a description ("Decoy entity generator for tactical misdirection.") and version v1.7.16 — evidence of structured internal development. The 130MB pad simultaneously defeats AV file-size scanning heuristics and exceeds the upload cap of many automated sandbox services.

Hologram performs aggressive layered anti-analysis before executing its second stage. Checks include VirtualBox BIOS string queries, sandbox-associated DLL enumeration, VM-prefixed MAC address detection, blacklisted username comparison, and a multi-attribute hardware fingerprint score over GPU, CPU core count, RAM, disk size, running process count, and screen resolution. The implant additionally requires real user activity via a mouse-movement gate, defeating sandboxes that do not simulate input. In wave 3 (Pathfinder), the driver-list enumeration was replaced by a BIOS string query, indicating active operator iteration on detection-evasion logic.

Stage 1 is a Base64+XOR (key 44) obfuscated PowerShell loader. It disables Microsoft Defender (kill, six exclusion paths covering C:\Users\Public\ and the redundant copy locations, cloud blocking off, behavior monitoring off), splits cmdlet names into string fragments to evade signature-based AMSI rules, and opens inbound Windows Firewall rules on TCP/57001, 57002, and 56001. The stage-2 framework is dropped into C:\Users\Public\ with redundant copies under the user''s Documents, Music, Pictures, and Videos folders to defeat single-path remediation.

Stage 2 is a six-binary modular framework — svc_service.exe, virtnetwork.exe, audioeq.exe, OneSync.exe, WinHealhCare.exe, and onedrive_sync.exe — packed with a custom internal packer ("stealth_packer") that shares a build environment with the wave-1 Huntress-documented February 2026 samples, anchoring continuity of operator identity across waves. Five binaries are 64-bit Rust; onedrive_sync.exe is the lone 32-bit Rust binary. The newest core binaries (virtnetwork.exe, audioeq.exe) were compiled 2026-04-27 — one week pre-publication — confirming active development. Persistence is established with a malicious OneDriveSync.lnk in the system Startup folder, supplemented by a WinLogon Userinit registry hijack, a privileged scheduled task, and COM hijacking. Process injection leverages the clroxide Rust crate (first criminal use) and reflective PE loading via memexec, with thread injection performed via direct NT system-call stubs to bypass user-mode EDR API hooks.

The C2 architecture pairs a primary server (assessed as a hijacked Brazilian law-firm domain) with a DigitalOcean-hosted secondary server. Stage-2 binaries are pulled from an attacker-controlled Azure DevOps organization (sagonbretzpr). Configuration data is retrieved via dead-drop resolvers on Telegram (channel b8bz11) and snippet.host. Most distinctively, victim telemetry — username, public IP, timestamp — is exfiltrated through Hookdeck''s hkdk.events relay (URL hkdk.events/djbk1i9hp0sqoh), abusing a legitimate webhook gateway to obscure backend infrastructure and survive blocklist takedowns. Hologram targets credentials from 250+ cryptocurrency wallet and password-manager browser extensions; Ledger Live is fetched as a separate module from a distinct URL. Wave 3 (Pathfinder), active during Netskope''s analysis, rotated primary and secondary C2, the Telegram dead-drop, the campaign tag, and added two stage-2 binaries — operator infrastructure resilience exceeds typical commodity stealer playbooks.

## MITRE ATT&CK

- T1583 Acquire Infrastructure
- T1608 Stage Capabilities
- T1189 Drive-by Compromise
- T1204.002 User Execution: Malicious File
- T1059.001 Command and Scripting Interpreter: PowerShell
- T1106 Native API
- T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
- T1547.004 Boot or Logon Autostart Execution: Winlogon Helper DLL
- T1546.015 Event Triggered Execution: Component Object Model Hijacking
- T1053.005 Scheduled Task/Job: Scheduled Task
- T1055 Process Injection
- T1620 Reflective Code Loading
- T1027.001 Obfuscated Files or Information: Binary Padding
- T1027.013 Obfuscated Files or Information: Encrypted/Encoded File
- T1685 Disable or Modify Tools
- T1686 Disable or Modify System Firewall
- T1497.001 Virtualization/Sandbox Evasion: System Checks
- T1497.002 Virtualization/Sandbox Evasion: User Activity Based Checks
- T1555.003 Credentials from Password Stores: Credentials from Web Browsers
- T1555.005 Credentials from Password Stores: Password Managers
- T1119 Automated Collection
- T1071.001 Application Layer Protocol: Web Protocols
- T1102.001 Web Service: Dead Drop Resolver
- T1102.002 Web Service: Bidirectional Communication
- T1041 Exfiltration Over C2 Channel

## Sources

- [OpenClaw's Hologram: Fake Installer Ships Rust Infostealer](https://www.netskope.com/blog/openclaw-hologram-fake-installer-ships-rust-infostealer)
- [MITRE ATT&CK T1620 — Reflective Code Loading](https://attack.mitre.org/techniques/T1620/)
- [MITRE ATT&CK T1102.001 — Dead Drop Resolver](https://attack.mitre.org/techniques/T1102/001/)
- [MITRE ATT&CK T1027.001 — Binary Padding](https://attack.mitre.org/techniques/T1027/001/)
- [MITRE ATT&CK T1546.015 — COM Hijacking](https://attack.mitre.org/techniques/T1546/015/)
- [MITRE ATT&CK T1547.004 — Winlogon Helper DLL](https://attack.mitre.org/techniques/T1547/004/)
- [MITRE ATT&CK T1497.002 — User Activity Based Checks](https://attack.mitre.org/techniques/T1497/002/)
- [MITRE ATT&CK T1562.001 — Disable or Modify Tools](https://attack.mitre.org/techniques/T1562/001/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0480
