CryptoShuffler is a Windows clipboard-hijacking cryptocurrency theft malware family identified in 2017 and active since at least 2016. It infects victim systems and remains largely idle until a user copies a cryptocurrency wallet address to the clipboard. The malware monitors clipboard contents for strings matching wallet formats and silently replaces them with attacker-controlled addresses, causing victims to transfer funds to the operator if they do not verify the pasted destination before completing a transaction. Reported targeting includes Bitcoin as well as other cryptocurrencies such as Dogecoin, Litecoin, Dash, Ethereum, Monero, and Zcash. The operation was notable for generating substantial illicit revenue through this simple address-substitution scheme, making CryptoShuffler one of the better-known early cryptocurrency-focused clipboard hijackers. CryptoShuffler has also appeared among payloads delivered in broader criminal malware distribution activity, including spam-driven campaigns that primarily spread other banking malware families.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
17 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as another malware family identified among some payloads in the broader campaign data.
Clipboard-hijacking cryptocurrency stealer (noted as first observed in 2017) that replaces copied cryptocurrency wallet addresses with attacker-controlled addresses to divert funds.
Earlier clipboard-hijacking malware family focused on replacing cryptocurrency wallet addresses to steal funds from victims.
Clipboard-hijacking malware that monitors victims' clipboards and swaps copied cryptocurrency wallet addresses with attacker-controlled addresses to divert payments.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.