Efimer is a Trojan and cryptocurrency-focused stealer/ClipBanker identified by Kaspersky, with activity assessed from at least October 2024 through July 2025. Kaspersky named it "Efimer" because that word appeared in a comment at the beginning of its decrypted script. Its core behavior is to steal cryptocurrency-related data and hijack transactions by replacing copied wallet addresses in the clipboard with attacker-controlled addresses. Reported targets include Bitcoin, Ethereum, and Monero wallets, with one torrent-delivered variant also spoofing Tron and Solana addresses. Efimer also steals mnemonic seed phrases from the clipboard, stores them temporarily in C:\Users\Public\controller\SEED, exfiltrates them, deletes the file, and captures screenshots after detecting mnemonic phrases.
Observed delivery vectors include compromised WordPress sites, malicious torrent lures, and phishing emails. In one June campaign, attackers impersonated lawyers alleging trademark infringement and delivered a ZIP archive named Demand_984175 (MD5: e337c507a4866169a7394d718bc19df9) containing a nested password-protected archive and an empty password file using Unicode character U+1D5E6 to hinder automated extraction. Execution of Requirement.wsf installed Efimer. Compromised WordPress sites were also used to host fake movie-download pages leading to password-protected archives and fake XMPEG packages; one observed lure was lovetahq[.]com/sinners-2025-torent-file/, and the package included xmpeg_player.exe as another Efimer installer.
On execution, the WSF installer checked for administrator privileges by attempting to write to C:\Windows\System32\wsf_admin_test.tmp. With elevated privileges it added C:\Users\Public\controller and several files or processes to Windows Defender exclusions and created persistence via a scheduled task using controller.xml. Without elevation it persisted through HKCU\Software\Microsoft\Windows\CurrentVersion\Run\controller and launched controller.js with WScript. Efimer also checked whether Task Manager was running and exited if detected.
Efimer downloaded a Tor proxy service from hardcoded URLs on compromised websites and saved it as C:\Users\Public\controller\ntdlg.exe. It communicated over Tor with at least one onion C2, cgky6bn6ux5wvlybtmm3z255igt52ljml2ngnc5qp3cnw5jlglamisad[.]onion, polled roughly every 30 minutes, and could execute arbitrary JavaScript returned in EVAL commands. It uploaded screenshots to recvf.php over Tor and reported both original and replacement wallet addresses after clipboard swaps. Victim identifiers were observed in formats including vs1a-XXXX and vt05-XXXX.
Kaspersky also linked auxiliary components and related scripts to the same operation. The script btdlg.js (MD5: 0f5404aa252f28c61b08390d52b7a054) brute-forced WordPress passwords using XML-RPC metaWeblog.newPost requests and /wp-json/wp/v2/users enumeration, sending successful credentials to C2 with the GOOD command. Another related script, liame.js, harvested email addresses from websites and likely supported spam or form-submission abuse. A related variant, assembly.js (MD5: 100620a913f0e0a538b115dbace78589), scanned browser extension and wallet application directories for cryptocurrency wallets, checked for virtualized environments, and communicated with a separate onion C2 at he5vnov645txpcv57el2theky2elesn24ebvgwfoewlpftksxp4fnxad[.]onion, supporting RPLY, EVAL, and KILL commands.
Separate reporting from Breakglass Intelligence assessed a NativeAOT .NET stealer delivered via ClickFix/FakeCaptcha and DLL sideloading as likely related to the ACRStealer/Efimer family. That stealer was described as capable of credential theft, cookie extraction, browser data harvesting, crypto wallet theft, and screenshot capture, and communicated over HTTPS/TLS 1.3. This linkage was assessed as likely rather than definitive.
Kaspersky reported 5,015 affected users from October 2024 through July 2025, with Brazil having the highest number of detections, followed by India, Spain, Russia, Italy, and Germany. Kaspersky detections for this threat include HEUR:Trojan-Dropper.Script.Efimer, HEUR:Trojan-Banker.Script.Efimer, HEUR:Trojan.Script.Efimer, and HEUR:Trojan-Spy.Script.Efimer.gen.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
For every new domain, this data is saved... For every new domain, the script makes a request using the WPTryPost function. This is an XML-RPC function that attempts to create a test post using a potential username and password.
In June, we detected a mass mailing campaign that was distributing identical messages with a malicious archive attached... The emails... claimed that lawyers from a large company had reviewed the recipient’s domain and found words or phrases in its name that infringed upon their registered trademarks.
Finally, it creates a scheduler task in Windows, using the configuration from controller.xml.
if the first line of the response contains an EVAL command, it means all subsequent lines are JavaScript code. This code will then be executed using the eval function.
The script then takes five screenshots... and sends them to the server as well. They are captured with the help of the following PowerShell command...
Its primary goal is to collect email addresses from specified websites and send them to the C2 server... The PageGetLiame function extracts email addresses from the page’s HTML content.
the script sends a POST request to the C2 using the curl utility, routing the request through a Tor proxy... The server’s response is saved to the user’s %TEMP% directory
46 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Efimer is referenced as a related malware family in the broader ClickFix ecosystem and as a likely family related to the NativeAOT .NET stealer delivered through DLL sideloading.
Trojan used to steal cryptocurrency from thousands of victims (per summary).
A trojan involved in banking-trojan activity; observed spreading via malicious email and compromised WordPress sites, consistent with credential/payment-data theft objectives described for PC banking trojans.
Efimer is a cryptocurrency-focused ClipBanker/Trojan that steals mnemonic seed phrases, replaces copied wallet addresses in the clipboard with attacker-controlled addresses, communicates with C2 over Tor, can execute additional JavaScript received from the server, and is used to spread further via compromised WordPress sites, malicious torrents, and phishing emails.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.