ClipXDaemon is a Linux cryptocurrency clipboard hijacker that targets users of X11-based desktop environments. It is designed for direct financial theft by monitoring clipboard contents at high frequency and replacing copied cryptocurrency wallet addresses with attacker-controlled alternatives before the victim pastes them into a transaction workflow. Reported targeting includes multiple wallet formats such as Bitcoin, Ethereum, Litecoin, Monero, Dogecoin, Tron, Ripple, and TON.
The malware operates without command-and-control infrastructure and has been characterized as autonomous and fully offline. Analyses reported no beaconing, remote tasking, DNS activity, HTTP traffic, or general socket communication. Instead of relying on external infrastructure, ClipXDaemon monetizes infections locally through clipboard manipulation alone.
Observed delivery involves a multi-stage infection chain built around a bincrypter-based loader. The initial stage decrypts and launches an intermediate dropper largely in memory, after which the dropper writes a randomized ELF payload into the user environment, launches it, and establishes persistence by modifying the user profile so the malware is re-executed during future logins. The final payload is a 64-bit Linux ELF linked against X11 libraries.
ClipXDaemon is tailored specifically for X11. It checks for Wayland and exits when Wayland is detected, reflecting Wayland’s stronger restrictions on global clipboard access. Under X11, the payload daemonizes, detaches from the terminal, and masquerades as a kernel worker-style process name to reduce suspicion. It then connects to the X server, polls clipboard selections roughly every 200 milliseconds, identifies cryptocurrency address patterns, and takes ownership of the clipboard selection to supply substituted wallet data at paste time.
The malware also employs basic defense-evasion measures. Reported samples used process masquerading and encrypted internal configuration data, including wallet-matching patterns and replacement values, to complicate static analysis. Public reporting noted structural similarities between the delivery chain used for ClipXDaemon and tooling previously seen with ShadowHS, but available information does not support attributing both to the same operator or campaign; the overlap is assessed as reuse of publicly available tooling rather than proof of common authorship.
ClipXDaemon represents a notable example of specialized Linux financial malware focused on cryptocurrency theft in desktop environments rather than broader remote access or botnet functionality.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
ClipXDaemon operates locally without network communication... and persists by modifying the user’s ~/.profile file.
ClipXDaemon operates locally without network communication... and persists by modifying the user’s ~/.profile file.
"executes the intermediate dropper directly through a /proc/self/fd file descriptor — never writing the decrypted stage to disk"
The loader uses AES-256-CBC encryption and gzip compression to conceal payload contents. The ELF configuration is further encrypted with ChaCha20.
The payload renames itself using prctl(PR_SET_NAME) to mimic kernel worker threads.
"executes the intermediate dropper directly through a /proc/self/fd file descriptor — never writing the decrypted stage to disk"
"checks whether the Wayland display server is present and exits immediately if detected"
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Linux clipper malware mentioned for comparison because it shares similarities in persistence locations and targeted cryptocurrencies with StealNui.
Linux-based cryptocurrency clipper malware that hijacks copied wallet addresses, replacing them with attacker-controlled addresses to steal cryptocurrency. It operates locally without network communication, disguises itself as a kernel process, and persists by modifying the user’s ~/.profile file.
Linux X11 clipboard hijacker (clipper) that monitors clipboard contents at high frequency and replaces detected cryptocurrency wallet addresses (e.g., Monero, Ethereum, Bitcoin, Litecoin, Dogecoin, Tron) with attacker-controlled addresses; uses persistence without root/systemd and double-fork daemonization; operates without C2 for direct monetization.
Linux clipboard hijacker that intercepts copy/paste operations and replaces cryptocurrency wallet addresses with attacker-controlled addresses.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.