sakaen736jih is a malicious developer account associated with a malware distribution campaign abusing AI ecosystems, particularly the OpenClaw ecosystem distributed through ClawHub. The account was attributed with publishing 199 malicious skills, representing a substantial share of the identified malicious content in that ecosystem. These skills were disguised as legitimate AI tools or agent extensions and were used to deliver trojans, infostealers, and cryptominers. Activity linked to this account formed part of a broader supply-chain-style abuse of trusted AI platforms in which malicious skill definitions and related artifacts were used to trick users and autonomous AI agents into executing attacker-controlled actions. Observed tradecraft included social engineering through trojanized utility-themed skills, hidden or encoded command execution, external payload retrieval, and indirect prompt injection embedded in skill files so that OpenClaw agents could carry out concealed malicious instructions on behalf of users. Associated payload behavior across the broader campaign included Windows and macOS malware delivery, in-memory process injection, encrypted command-and-control, persistence through scheduled tasks, defense evasion through security control modification, and deployment of AMOS Stealer and cryptomining malware. The campaign demonstrates a blend of initial access through trusted AI repositories, post-exploitation malware staging, credential-focused theft via infostealers, and stealth techniques designed to evade user scrutiny and endpoint protections. No high-confidence attribution to a nation state, formal intrusion set, or specific sub-group is currently available for sakaen736jih beyond its role as a malicious publisher account within this campaign.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.