@JoseCmanXD is a financially motivated cybercriminal handle associated with a cryptocurrency theft campaign centered on clipper malware. The actor promoted trojanized cryptocurrency and gambling-related tools, including purported Solana sniper bots and game-prediction utilities, to lure users seeking quick-profit opportunities. The operation relied heavily on social proof manipulation across multiple online platforms, including fabricated popularity metrics, coordinated positive commentary, and other reputation-enhancement tactics intended to make malicious software appear trustworthy and widely used. The malware associated with this activity was a clipboard hijacker designed to monitor copied cryptocurrency wallet addresses and silently replace them with attacker-controlled alternatives, redirecting victim transfers. Delivery mechanisms included a Windows loader chain involving a .NET component and a macOS execution path that attempted to bypass native platform protections. The payload was described as Rust-based and operated in the background after execution. The actor demonstrated capability in malware distribution, defense evasion through trust manipulation and platform abuse, and cryptocurrency theft through clipboard interception. The campaign also showed deliberate cross-platform promotion using code-hosting sites, download portals, video tutorials, cryptocurrency forums, and reputation systems commonly consulted by users and defenders. No high-confidence attribution to a nation-state or specific geographic origin is currently available.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.