CTIPilot

OpenClaw agent-phishing disclosures

campaign · campaign:openclaw-prompt-injection-agent-phishing-2026

OpenClaw AI agent abuse research: indirect prompt injection (Imperva) and agent phishing (Varonis).

Coverage timeline
1
first 2026-06-12 → last 2026-06-12
Peak priority
notable
1 notable
Sources cited
3
3 hosts
Sections touched
1
research
Co-occurring entities
0
no co-occurrence
ATT&CK techniques
1
pinned v19.2 · see below

Hunting pivots

ATT&CK techniques

1 technique observed across 1 entry, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Execution TA0002

T1059Command and Scripting Interpreter×1

Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries. These interfaces and languages provide ways of interacting with computer systems and are a common feature across many different platforms. Most systems come with some built-in command-line interface and scripting capabilities, for example, macOS and Linux distributions include some flavor of Unix Shell while Windows installations include the Windows Command Shell and PowerShell.

Evidence: 2026-06-12/imperva-and-varonis-indirect-prompt-injection-and-agent-phis · ATT&CK page ↗

Story timeline

  1. 2026-06-12Imperva and Varonis: indirect prompt injection and "agent phishing" against the OpenClaw AI agent, fixed in v2026.4.23, but the attack class generalises
    research

Where this entity is cited

  • research1

Source distribution

  • attack.mitre.org1 (33%)
  • imperva.com1 (33%)
  • varonis.com1 (33%)

explore in graph

Entries about OpenClaw agent-phishing disclosures (1)

2026-06-12 · view entry permalink →

NOTABLE

Imperva and Varonis: indirect prompt injection and "agent phishing" against the OpenClaw AI agent, fixed in v2026.4.23, but the attack class generalises

Two independent teams published complementary findings against OpenClaw, the self-hosted AI-agent platform that plugs into messaging systems, mailboxes, file systems and APIs. Imperva showed that shared contact names, vCard fields and location-pin labels flow into the LLM prompt with no untrusted-content boundary: a crafted contact (its injected command hidden behind 65 whitespace characters so the UI truncates it) executed python3 on the victim's host the moment the victim shared the contact with their agent (Imperva, 2026-06-10). Varonis demonstrated "agent phishing": a plain email from a plausible sender persuaded a mailbox-connected agent to forward mock AWS IAM keys and a customer export to an external address, with no exploit involved; the agent simply lacks sender-identity verification before acting (Varonis, 2026-06-09). Both teams note OpenClaw's default memory persistence lets one successful injection survive across sessions. The vendor fix (v2026.4.23) moves messaging-object metadata into a separate untrusted channel, but the structural lesson stands: wherever an agent ingests third-party-controlled strings (contacts, calendar invites, ticket bodies), that channel is an injection surface (T1059). Defender takeaway: pin OpenClaw ≥ v2026.4.23; inventory which AI agents hold mailbox send-permissions or shell access; gate agent-initiated outbound actions behind approval workflows the same way you gate privileged operations.

research12 Jun 05:00Zmulti-sourceOpen finding ↗
Sources: Imperva · Varonis