Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
mttaggart@infosec.exchangeM

mttaggart@infosec.exchange

@mttaggart@infosec.exchange
About
Indlæg
9
Emner
1
Fremhævelser
0
Grupper
0
Følgere
0
Følger
0

Vis Original

Indlæg

Seneste Bedste Controversial

  • I am convinced we are on the verge of the first "AI agent worm".
    mttaggart@infosec.exchangeM mttaggart@infosec.exchange

    @mcc @dvshkn @cwebber It's very easy and being done, although in big places you'll hear screams from your devs. api.anthropic[.]com can be blocked today.

    Ikke-kategoriseret

  • I am convinced we are on the verge of the first "AI agent worm".
    mttaggart@infosec.exchangeM mttaggart@infosec.exchange

    @dvshkn @mcc @cwebber So the trick here is if you install OpenClaw in secret on a user's machine who isn't checking carefully, you might hide easily in network traffic. Use of tools like Claude Code would make the same API calls, which is likely for users who would be targeted with these attacks.

    The real insane part is if multiple instance of OpenClaw were running on the same machine, so not even the process name looked suspicious. But of course process names are a poor indicator and can be changed.

    Ikke-kategoriseret

  • I am convinced we are on the verge of the first "AI agent worm".
    mttaggart@infosec.exchangeM mttaggart@infosec.exchange

    @mcc @cwebber You could, but I would not recommend doing so. Instead perhaps a purposed YARA lookup with a single rule to look for the filename/string? Not sure why you'd be so restrictive on detections, but you can.

    Ikke-kategoriseret

  • I am convinced we are on the verge of the first "AI agent worm".
    mttaggart@infosec.exchangeM mttaggart@infosec.exchange

    @mcc @cwebber I concur with the assessment, and have been sharing similar warnings. In fact, we are beginning to see a pivot in stealer activity to install OpenClaw, etc. for exactly these purposes. It's a botnet, compute miner, and worm all in one.

    Ikke-kategoriseret

  • OpenClaw is indistinguishable from malware and should be treated as such in enterprise networks.
    mttaggart@infosec.exchangeM mttaggart@infosec.exchange

    @FritzAdalis @Sempf That's just the default though, and shouldn't be the only check. Luckily, since openclaw is the binary, you can also just look for process creation.

    Ikke-kategoriseret

  • OpenClaw is indistinguishable from malware and should be treated as such in enterprise networks.
    mttaggart@infosec.exchangeM mttaggart@infosec.exchange

    @FritzAdalis @Sempf Tanium too, methinks. The easiest tell is the openclaw folder, which is created regardless of install method.

    The network detections are rough. 18789/tcp has a lot of false positives, and also the modern installation is not open by default. It also can use Tailscale for exposure, so you'll see Wireguard traffic, but not OpenClaw.

    Ikke-kategoriseret

  • OpenClaw is indistinguishable from malware and should be treated as such in enterprise networks.
    mttaggart@infosec.exchangeM mttaggart@infosec.exchange

    @Sempf Without chasing down binary hashes, this is the best I've found for detection/remediation: https://github.com/knostic/openclaw-detect

    Ikke-kategoriseret

  • OpenClaw is indistinguishable from malware and should be treated as such in enterprise networks.
    mttaggart@infosec.exchangeM mttaggart@infosec.exchange

    OpenClaw is indistinguishable from malware and should be treated as such in enterprise networks.

    Do what you want with your own data and gear, but bring that garbage onto my network and I am locking all phaser banks.

    https://www.404media.co/meta-director-of-ai-safety-allows-ai-agent-to-accidentally-delete-her-inbox/

    Ikke-kategoriseret

  • This whole "OpenClaw" thing has made me very angry and I wrote a bit about the why.
    mttaggart@infosec.exchangeM mttaggart@infosec.exchange

    @tante @stefan_hessbrueggen In the thread!

    Ikke-kategoriseret
  • Log ind

  • Har du ikke en konto? Tilmeld

  • Login or register to search.
Powered by NodeBB Contributors
Graciously hosted by data.coop
  • First post
    Last post
0
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper