hightower6eu is a malicious publisher associated with a large-scale malware distribution campaign abusing the OpenClaw ecosystem and its public marketplace, ClawHub. The actor was attributed with publishing more than 300 trojanized skills, representing the majority share of identified malicious OpenClaw packages in the observed campaign. These skills were disguised as legitimate utilities, including finance, cryptocurrency, and social-media themed tools, but were designed to socially engineer users into downloading and executing external payloads or running obfuscated commands. The actor’s tradecraft centered on supply-chain abuse of trusted AI-agent extension ecosystems rather than exploitation of a software vulnerability. Malicious skills were crafted to appear useful while embedding instructions that caused users, or autonomous AI agents acting on users’ behalf, to retrieve and launch malware from external sources. Observed payloads included Windows trojans, a cryptominer, and the macOS-focused Atomic Stealer (AMOS). Reported Windows activity included runtime string decryption, dynamic API resolution, in-memory process injection into explorer.exe, encrypted command-and-control over HTTPS, persistence through scheduled tasks, and modification of Windows Defender exclusions. Reported macOS activity included silent download and execution of AMOS to steal credentials, browser data, cookies, and cryptocurrency wallet data, followed by exfiltration and self-deletion. The campaign also demonstrated abuse of indirect prompt injection within OpenClaw skill definitions. Because OpenClaw agents can execute commands autonomously with the user’s permissions, hidden instructions in skill files could induce agent-driven execution of malicious actions, extending the actor’s reach beyond conventional social engineering. The activity is best characterized as financially motivated malware distribution and credential theft conducted through AI-platform supply-chain abuse.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Primary actor in a malicious ClawHub/OpenClaw supply-chain-style campaign publishing trojanized AI skills disguised as legitimate tools to deliver trojans, cryptominers, and infostealers.
Operates a supply-chain style campaign against the OpenClaw (formerly Clawdbot) AI agent ecosystem by publishing large volumes of malicious “skills” to the ClawHub marketplace. The skills use social engineering to instruct users to download/execute external code, leading to malware installation (including Atomic Stealer/AMOS on macOS and a trojanized payload via password-protected ZIP on Windows).
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.