Android.Clipper.31 is an Android cryptocurrency-stealing trojan reported by Doctor Web in April 2025. It was found preinstalled in the firmware of several budget Android smartphone models as part of a supply-chain compromise affecting several Chinese manufacturers. The malware was embedded in a modified WhatsApp messenger that was preinstalled on affected devices; Doctor Web also reported it was built into a modified WhatsApp using the LSPatch tool to alter app logic without changing code. In addition, Doctor Web stated that Android.Clipper.31 was embedded into dozens of other modified apps, including cryptocurrency wallets, QR scanners, and messengers such as Telegram, distributed via malicious websites. Its core behavior is to intercept messages, search for Tron and Ethereum wallet addresses, and replace them with attacker-controlled addresses while concealing the substitution from victims. Doctor Web also reported that it exfiltrates JPG, PNG, and JPEG images to threat actors in order to search for saved mnemonic phrases that could provide access to cryptocurrency wallets. The malware targeted Android devices, particularly users of affected budget smartphones and users installing trojanized Android apps, with the apparent objective of cryptocurrency theft.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android clipper/crypto-stealing trojan embedded into device firmware and also distributed via modified apps; replaces Tron/Ethereum wallet addresses in messages with attacker-controlled addresses while visually concealing the substitution, and exfiltrates images to hunt for wallet mnemonic phrases.
Supply-chain/preinstall firmware threat embedded in a trojanized WhatsApp; intercepts messages, searches for Tron/Ethereum wallet addresses, replaces them with attacker-controlled addresses while visually concealing the substitution from the victim.
Supply-chain/firmware-embedded Android clipper that intercepts messages in a trojanized WhatsApp, searches for Tron/Ethereum wallet addresses, and replaces them with attacker-controlled addresses while concealing the substitution from the victim.
Android clipper trojan embedded via supply-chain/firmware and trojanized apps (e.g., WhatsApp mods). It replaces Tron/Ethereum wallet addresses in messages with attacker-controlled ones while showing victims the original addresses, and exfiltrates images to search for mnemonic phrases.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.