ZigCryptoStealer is a Zig-based Windows cryptocurrency clipper deployed in ClearFake ClickFix infection chains. It is launched through DLL side-loading involving a legitimate Google Chrome component and a NativeAOT loader, which injects the payload into a suspended Explorer process. The malware monitors the Windows clipboard for recognized cryptocurrency wallet-address formats and substitutes attacker-controlled addresses, redirecting victim cryptocurrency transfers. Associated deployment tooling uses a signed vulnerable driver in a bring-your-own-vulnerable-driver attack to terminate identified EDR and security-product processes. ZigCryptoStealer retrieves mutable command-and-control configuration from BNB Smart Chain smart contracts using EtherHiding, allowing operators to rotate infrastructure without replacing the endpoint payload. Delivery has been linked to compromised websites that present fake CAPTCHA-style ClickFix prompts and persuade users to execute commands that retrieve subsequent stages over WebDAV.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
29 distinct techniques documented for this family, organized by ATT&CK tactic.
MITRE ATT&CK™ Matrix - Windows ... Defense Evasion ... File System Logical Offsets
MITRE ATT&CK™ Matrix - Windows ... Defense Evasion ... Software Packing
The NativeAOT DLL starts "C:\Windows\"explorer.exe" in a suspended state, manually maps the PE’s headers and sections into the child, changes its initial thread context to the new entry point, and resumes it.
“This is a bring-your-own-vulnerable-driver, or BYOVD, attack.”
“[The command] calls rundll32, a legitimate Windows utility, to execute a library export identified only by a number.”
Data Collection Combination of other detections shows multiple input capture behaviors ... MITRE ATT&CK™ Matrix - Windows ... Credential Access Input Capture
It polls the clipboard, recognizes several cryptocurrency address formats and can replace matching values with addresses embedded in the payload.
“The loader searches for EDR products and sends matching process identifiers to the driver.”
MITRE ATT&CK™ Matrix - Windows ... Discovery System Information Discovery
MITRE ATT&CK™ Matrix - Windows ... Discovery File and Directory Discovery
MITRE ATT&CK™ Matrix - Windows ... Collection ... Data from Local System
Data Collection Combination of other detections shows multiple input capture behaviors ... MITRE ATT&CK™ Matrix - Windows ... Credential Access Input Capture
It polls the clipboard, recognizes several cryptocurrency address formats and can replace matching values with addresses embedded in the payload.
Data Collection Takes screenshot 1 ... MITRE ATT&CK™ Matrix - Windows ... Collection Data Screen Capture
Network Connection Uses HTTP to upload a large amount of data ... MITRE ATT&CK™ Matrix - Windows ... Command and Control Standard Application Layer Protocol
14 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A cryptocurrency stealer deployed through ClearFake's DLL side-loading chain. It monitors and replaces copied cryptocurrency wallet addresses, uses EtherHiding and a BNB Smart Chain contract for changing C2 configuration, and is paired with a vulnerable driver that terminates EDR processes.
A cryptocurrency stealer deployed by ClearFake that uses a vulnerable signed driver to terminate EDR processes, monitors the clipboard for cryptocurrency wallet addresses, and substitutes attacker-controlled addresses. It uses EtherHiding through a BNB Smart Chain contract to retrieve changing C2 configuration.
A Zig-written cryptocurrency stealer and clipboard hijacker. It monitors and substitutes cryptocurrency wallet addresses in the clipboard, and uses a BNB Smart Chain contract as an EtherHiding dead drop to obtain its C2 domain. Its loader also deploys a vulnerable signed driver to terminate EDR and other security processes.
A Zig-based cryptocurrency stealer that monitors the clipboard for cryptocurrency addresses and replaces recognized address formats with attacker-controlled addresses. It uses a BNB Smart Chain contract as an EtherHiding dead drop to obtain its C2 domain.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.