Clawdbot Malware

Clawdbot Malware

🎙 John Hammond 👥 2.2M 📅 January 27, 2026 ⏱ 43 min 👁 116K 📄 expert opinion 🧭 2026-08-16
Available in: English (current) Français

Keywords

ClawdbotmalwareVS Code extensionScreenConnectRAT

Summary

John Hammond dissects a fake Clawdbot VS Code extension that installs a remote access trojan. He begins by explaining the context: the real Clawdbot (now Moltbot) is an AI assistant, and threat actors are exploiting its hype. He downloads the malicious extension and examines its code, revealing that it fetches a config file and attempts to download and execute additional payloads. However, due to coding errors, the malware fails to detonate properly. He explores the fallback mechanism, which downloads a legitimate VS Code executable and a dummy DLL, but again fails. He then investigates a batch script that points to a dark web URL, leading to an ‘Evelyn panel’ – an info stealer campaign. He cross-references with Trend Micro and Koi Security reports, noting similarities but also differences. The video concludes that the malware is poorly constructed, likely ‘vibe coded’, and not fully functional, but highlights the real threat of malicious VS Code extensions.

154 words

Critical Evaluation

Value of the Information & Strength of the Argument

The video provides high value by demonstrating a real-world malware analysis process, including code inspection, dynamic analysis, and threat intelligence correlation. The argumentation is solid, based on direct observation and technical evidence. Hammond clearly explains each step, making the analysis accessible without oversimplifying. He also engages with the audience by asking for feedback on potential misinterpretations, showing intellectual honesty.

Scientific Rigor, Source Quality, Title Accuracy

The video demonstrates strong scientific rigor by referencing multiple reputable sources: Aikido’s blog, Trend Micro’s analysis of the Evelyn stealer, and Koi Security’s research. Hammond also uses tools like IDA Pro and VirusTotal, adding credibility. The title accurately reflects the content, focusing on the Clawdbot malware. The analysis is thorough, though some parts are speculative due to the malware’s broken state. The video also includes a sponsored segment, which is clearly disclosed.

146 words

Title / Content Match

The title accurately reflects the content, focusing on the Clawdbot malware and its analysis.

Quality & Reliability

8/10

The video provides a detailed technical analysis of a malicious VS Code extension, with hands-on reverse engineering and references to reputable sources. The analysis is thorough, but some conclusions are speculative due to the malware's broken state.

Key Moments

Cited Sources

Concurring Sources

Dissenting Sources

External References

Contribution & Novelties

This video provides a unique, hands-on analysis of a specific malware campaign, showing the actual code and its failures. It highlights the trend of ‘vibe coding’ malware, where AI-generated code is poorly constructed. The analysis also connects the malware to the broader Evelyn stealer campaign, offering insights into threat actor tactics.

Pour aller plus loin :

  • VS Code Extension Security — Official documentation on VS Code extension security.
  • DLL Hijacking — Wikipedia article on DLL hijacking, a technique used in this malware.
  • ScreenConnect RAT — Official page for ScreenConnect, the remote access tool abused in this campaign.

97 words

Radar Profile

The radar profile shows high scores in information quantity and technical level, indicating a detailed and technical analysis. The quality and reliability scores are also high, reflecting the use of credible sources and hands-on investigation. The overall profile suggests a well-rounded, informative video.

Reliability 8/10

💬 Très positif. Sur les 30 commentaires analysés, la majorité exprime de l'appréciation pour l'analyse détaillée et le côté éducatif, avec des remarques humoristiques sur le 'vibe coding' du malware.