Threat researchers reported active cryptocurrency-focused malware campaigns that rely on social engineering and deceptive executables to steal funds or wallet-related secrets. One operation observed by CloudSEK targets Discord communities tied to gaming, gambling, and crypto streaming, where an actor tracked as “RedLineCyber” builds trust and privately shares Windows executables (e.g., Pro.exe, peeek.exe) pitched as streaming/security tools. After installation, the malware performs clipboard hijacking, monitoring for copied wallet addresses and swapping them with attacker-controlled addresses at paste time, enabling theft with minimal user-visible indicators and limited/no obvious command-and-control activity.
Separately, Iru researcher Calvin So documented MonetaStealer on macOS, delivered as Portfolio_Review.exe but actually an unsigned Mach-O binary using a misleading .exe extension to exploit the assumption that Windows executables are harmless on Macs. The sample is Python-based and bundled with PyInstaller, with core logic hidden in a compressed portfolio_app.pyc, and was reported as having zero detections on VirusTotal at the time of analysis. MonetaStealer is designed to steal cryptocurrency wallet data along with browser secrets and Keychain information, and appears to be early-stage malware with indications of AI-assisted code structure.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Researchers reported that the Python/PyInstaller malware persistently monitored victims' clipboards and swapped copied cryptocurrency wallet addresses with attacker-controlled ones at paste time. Blockchain tracing tied the operation to theft involving Bitcoin, Ethereum, Solana, Dogecoin, Litecoin, and Tron.
CloudSEK analysts linked a cryptocurrency clipboard-hijacking campaign targeting gamers and streamers on Discord to a threat actor tracked as "RedLineCyber" using a fake "RedLine Solutions" persona. The actor reportedly built trust in gaming, gambling, and crypto-streaming communities before sending malicious Windows executables such as Pro.exe and peeek.exe.
In the same investigation, Iru identified a second Windows-labeled variant designed to display a fake portfolio interface via Tkinter. The sample reportedly contained dead logic and placeholders and did not successfully run.
Researchers at Iru reported a new macOS infostealer dubbed MonetaStealer, distributed as a fake .exe file named "Portfolio_Review.exe" that is actually an unsigned Mach-O binary. The malware targets Chrome data, cryptocurrency wallets, Keychain contents, and Wi‑Fi credentials on macOS.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcesecurityonline.info
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.