AnimateClipper is a cryptocurrency clipper malware family delivered in a large-scale fake-software download campaign documented by Check Point Research. The campaign used more than 100 spoofed websites impersonating popular tools such as Ghidra, dnSpy, ILSpy, SpiderFoot, and CrystalDiskMark, with CloudFront-hosted JavaScript and a Traffic Distribution System to selectively route victims. One delivery path used a ClickFix lure: a fake Cloudflare verification page instructed users to execute a remote script via mshta.exe, including an observed URL to https://185.0xA1.0xFB[.]58/navy.7z. The infection chain involved obfuscated VBScript, PowerShell, RC4 decryption, a bundled Python environment, a hidden loader in a deceptive file named node_modules.asar, and in-memory shellcode execution via ntdll!LdrCallEnclave before loading the final PE payload. AnimateClipper silently monitors the clipboard and replaces copied cryptocurrency wallet addresses with attacker-controlled addresses embedded in the binary, enabling transaction hijacking across more than 20 blockchain ecosystems. Check Point reported that the malware could resolve command-and-control by querying a smart contract through the BNB Smart Chain Testnet JSON-RPC endpoint; at the time of analysis, the contract response resolved to kr.hugo-lapp[.]co. Researchers also observed attacker wallet activity associated with the sample dating back to 2025-07-12 on the BNB Smart Chain Testnet, indicating the operation had likely been active for an extended period. The malware is associated with the same broader campaign that also distributed RemusStealer and the SessionGate loader, with notable victim telemetry reported from countries including the U.K., Germany, France, Poland, Brazil, Russia, and Turkey.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
регистрация доменов - на T1583.001 (Domains). Атакующие инвестируют в подготовку инфраструктуры задолго до раздачи пейлоадов
This kicks off a complex chain involving PowerShell, RC4 decryption, a Python environment, and a hidden loader inside a deceptive file (node_modules.asar).
Its beginning contains an HTA page with obfuscated VBScript, which mshta.exe executes.
This kicks off a complex chain involving PowerShell, RC4 decryption, a Python environment, and a hidden loader inside a deceptive file (node_modules.asar).
These pages load a CloudFront-hosted JavaScript staging layer that converts a click on a “download” button/link into a handoff to a Traffic Distribution System (TDS). The TDS enforces strict gating: first-visit state, mandatory click confirmation, anti-bot/anti-analysis logic, VPN/datacenter filtering, and frequency capping.
SessionGate — A previously unknown multi-stage loader with heavy obfuscation and extensive anti-analysis mechanisms... Because of the obfuscation techniques in use, including injected junk code, opaque predicates, and string encryption, the resulting functions become extremely bloated.
This unknown multi-stage loader disguises itself as a 7-Zip SFX installer... AnimateClipper: Using the ClickFix technique, a fake Cloudflare verification screen tricks users into running a remote script via mshta.exe.
The obfuscated script embeds a large shellcode blob directly in its body and launches it from memory. It copies the shellcode into a buffer, changes the memory protection to executable, and transfers execution to it via ntdll!LdrCallEnclave.
This kicks off a complex chain involving PowerShell, RC4 decryption... requiring a one-time key from yourfastcrc.com to decrypt subsequent payloads.
These pages load a CloudFront-hosted JavaScript staging layer that converts a click on a “download” button/link into a handoff to a Traffic Distribution System (TDS). The TDS enforces strict gating: first-visit state, mandatory click confirmation, anti-bot/anti-analysis logic, VPN/datacenter filtering, and frequency capping.
Using the ClickFix technique, a fake Cloudflare verification screen tricks users into running a remote script via mshta.exe.
Immediately after browsers, it turns to targeting extensions like 1Password, Bitwarden, MetaMask, and Trust Wallet, exfiltrating screenshots and clipboard data (CF_UNICODETEXT) to C2 domains... The final payload replaces cryptocurrency addresses in the system clipboard with the hacker’s own.
The stealer polls the C2 using HTTP POST requests ... The malware uses HTTPS to communicate with the resolved C2 server. In the analyzed build, the observed logic includes periodic refresh check-ins
Маршрутизация Multi-hop Proxy (T1090.003, C2) TDS-цепочка из 4+ промежуточных нод для обфускации
These pages load a CloudFront-hosted JavaScript staging layer that converts a click on a 'download' button/link into a handoff to a Traffic Distribution System (TDS). The TDS enforces strict gating: first-visit state, mandatory click confirmation, anti-bot/anti-analysis logic, VPN/datacenter filtering, and frequency capping.
These pages load a CloudFront-hosted JavaScript staging layer that converts a click on a “download” button/link into a handoff to a Traffic Distribution System (TDS). The TDS enforces strict gating: first-visit state, mandatory click confirmation, anti-bot/anti-analysis logic, VPN/datacenter filtering, and frequency capping.
30 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Криптоклиппер, который подменяет адреса криптокошельков в буфере обмена; поддерживает более 20 блокчейн-экосистем.
A multi-stage clipboard hijacker delivered through a fake verification lure and ClickFix-style execution chain. It uses mshta.exe, PowerShell, RC4 decryption, a Python environment, and a hidden loader to run shellcode, then replaces cryptocurrency wallet addresses in the clipboard with attacker-controlled ones.
Clipboard-monitoring malware that replaces copied cryptocurrency wallet addresses with attacker-controlled addresses to divert funds.
A cryptocurrency clipper that replaces copied wallet addresses in the clipboard to hijack transactions across more than 20 blockchain ecosystems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.