Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to malware
Malware

stealth packer

Stealth Packer is a previously undocumented malware packer/implant framework observed in fake OpenClaw installer campaigns in 2026. It is associated with the Rust-based Hologram/Pathfinder activity and earlier Huntress-observed malicious GitHub installer campaigns. The malware shares the internal project name "stealth_packer," and Huntress also identified a PDB reference to stealth_packer and a mutex named Global\StealthPackerMutex_9A8B7C in related samples.

High-confidence reporting describes Stealth Packer as a post-exploitation implant used alongside a large padded Rust dropper and Telegram-bot update droppers. It was delivered through trojanized OpenClaw installers distributed via a fake site at openclaw-installer.com and typosquatted or malicious GitHub repositories impersonating OpenClaw installers. The broader campaign targeted credentials and data from cryptocurrency wallets including Ledger and MetaMask, more than 250 browser extensions, password managers, and 2FA authenticators; Huntress also noted broad targeting of users searching for OpenClaw installers rather than a specific industry.

Capabilities directly attributed in the content include in-memory malware execution/injection, firewall rule modification, creation of hidden or ghost scheduled tasks, and possible anti-VM or anti-sandbox mouse-movement checks. Netskope’s reporting on the associated framework describes additional behavior across the stage-2 binaries sharing the stealth_packer project name: anti-analysis checks, retrieval of payload passwords from Telegram dead-drop services, staging via Azure DevOps, C2 relay through Hookdeck, HTTPS beaconing, in-memory .NET execution via clroxide, reflective PE loading via memexec, persistence via startup LNKs, Run registry autoruns, WinLogon Userinit hijacking, scheduled tasks, and COM hijacking, plus thread injection using direct NT syscalls. The campaign used Telegram channel descriptions as dead-drop infrastructure for C2 resolution.

Associated infrastructure and artifacts mentioned in the content include openclaw-installer.com, Azure DevOps staging, Hookdeck relay infrastructure, Telegram dead-drop channels, the primary C2 frr.rubensbruno.adv.br in the Hologram wave, and YARA coverage for the Stealth Packer implant in a hologram.yar file. The malware is linked in reporting to the Hologram and Pathfinder campaign waves and to fake OpenClaw installer operations documented by Netskope Threat Labs and Huntress.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

MITRE ATT&CK

Techniques & procedures

9 distinct techniques documented for this family, organized by ATT&CK tactic.

Execution

1 technique
T1053.005Scheduled TaskEvidence1

Stealth Packer is a new packer that... creates hidden ghost scheduled tasks... EdgeUpdateHelper Scheduled Task ... Set to run ... AdobeCloudHelper.exe daily

Persistence

1 technique
T1053.005Scheduled TaskEvidence1

Stealth Packer is a new packer that... creates hidden ghost scheduled tasks... EdgeUpdateHelper Scheduled Task ... Set to run ... AdobeCloudHelper.exe daily

Privilege Escalation

1 technique
T1053.005Scheduled TaskEvidence1

Stealth Packer is a new packer that... creates hidden ghost scheduled tasks... EdgeUpdateHelper Scheduled Task ... Set to run ... AdobeCloudHelper.exe daily

Stealth

4 techniques
T1027Obfuscated Files or InformationEvidence1

Defender is killed in full... with every cmdlet name string-fragmented at runtime to defeat static PS1 detection rules.

T1027.002Software PackingEvidence1

hologram.yar : Yara rules to identify the Hologram/Pathfinder dropper, Stealth Packer implant, packed in-memory loader, and Telegram-bot dropper components

T1497Virtualization/Sandbox EvasionEvidence1

Stealth Packer is a new packer that... performs potential AntiVM checks for mouse movement before running decrypted payloads... Main installer, fails to execute if detected executing in a virtual environment.

T1620Reflective Code LoadingEvidence1

Stealth Packer is a new packer that injects malware into memory... The vast majority of executables were loaders created in Rust designed to run information stealers in memory.

Discovery

1 technique
T1497Virtualization/Sandbox EvasionEvidence1

Stealth Packer is a new packer that... performs potential AntiVM checks for mouse movement before running decrypted payloads... Main installer, fails to execute if detected executing in a virtual environment.

Command and Control

3 techniques
T1071Application Layer ProtocolEvidence1

with staging via Azure DevOps and C2 relay through Hookdeck

T1102Web ServiceEvidence1

The implant resolves its primary C2 domain from a Telegram channel description before any of the stage 2 modules run. | The operator abuses Azure DevOps, Telegram, and Hookdeck as infrastructure—legitimate services inside most enterprise allowlists.

T1105Ingress Tool TransferEvidence1

The campaign uses a large padded Rust dropper, a post-exploitation implant (Stealth Packer), and Telegram-bot update droppers

Other

1 technique
T1562.004Disable or Modify System FirewallEvidence1

Stealth Packer is a new packer that injects malware into memory, adds firewall rules...

INDICATORS OF COMPROMISE

IOCs tracked for this family

33 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
22 tracked

IPs, domains, and DNS infrastructure linked to this family.

Hashes
7 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

Other
4 tracked

Other indicator types observed in public reporting.

TypeValueLatest sighting
ip.v4●●●●●●●●●●●●View more in apptoday
domain●●●●●●●●●●●●View more in apptoday
domain●●●●●●●●●●●●View more in app1 day ago
domain●●●●●●●●●●●●View more in app1 month ago
domain●●●●●●●●●●●●View more in app1 month ago
uri●●●●●●●●●●●●View more in app1 month ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching33

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping9

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.