Multiple threat reports describe widespread use of clipper malware that monitors a victim’s clipboard for cryptocurrency wallet addresses and silently replaces them with attacker-controlled values, redirecting funds during transactions. Researchers documented this behavior in standalone families and MaaS offerings including AvD crypto stealer, Clipminer, Laplas Clipper, WeSteal, Evrial, Android.Clipper, and clipper modules bundled into platforms such as Eternity Project and Cinoshi. Several operations expanded beyond simple wallet replacement to target multiple cryptocurrencies, Steam trade links, and digital payment identifiers, while some samples used lookalike wallet prefixes to reduce user suspicion.
The malware has been delivered through trojanized software, cracked applications, spam attachments, phishing documents, fake developer tools, and broader malware chains that also deploy stealers, miners, RATs, botnets, or ransomware. Reports tied clipboard hijacking to campaigns involving ViperSoftX, OriginBotnet, DarkCloud, Tor2Mine, and a trojanized dnSpy installer, showing that clipboard abuse is often one component of larger financially motivated intrusions. MITRE tracks the underlying behavior as T1115 Clipboard Data, underscoring that clipboard collection and modification remain common techniques for credential theft, fraud, and cryptocurrency theft across Windows and Android environments.

Track how attackers are adapting to this technology.
25 events from the most recent confirmed update back to the earliest known activity.
On July 30, 2024, CYFIRMA published a report analyzing Mint Stealer as a malware-as-a-service offering sold through mint-stealer[.]top and mint-c2[.]top. The malware stole browser, wallet, gaming, messaging, VPN, FTP, system, and clipboard data, then uploaded archives to public file-sharing services before notifying its C2.
The analyzed Mint Stealer Setup.exe sample carried a modified date of 2024-06-23. The dropper extracted and launched a Nuitka-compiled Python payload named vadimloader.exe from its resources.
Cyble Research and Intelligence Labs reported that the Cinoshi malware-as-a-service platform surfaced on a cybercrime forum in March 2023. The platform offered a free stealer and paid botnet, clipper, and cryptominer capabilities.
Talos reported that MortalKombat ransomware was first observed by researchers in January 2023. Talos later assessed with high confidence that it belongs to the Xorist ransomware family.
Cisco Talos observed a financially motivated campaign beginning in December 2022 in which an unidentified actor deployed MortalKombat ransomware and a Go variant of Laplas Clipper. The campaign used CoinPayments-themed phishing emails and scanning for exposed RDP services.
Cisco Talos stated that Laplas Clipper was first observed by researchers in November 2022. The malware monitored clipboard wallet addresses and replaced them with attacker-controlled lookalike addresses.
K7 Labs analyzed a .NET-based cryptocurrency clipboard hijacker dubbed CryptoClipWatcher.exe that replaced copied wallet addresses with attacker-controlled ones. The report said it was commonly spread through Discord crypto communities and possibly email attachments, and documented persistence via the Startup folder, a Run key, and a scheduled task, with at least one attacker wallet receiving about $100.
On October 12, 2021, Avast published research attributing a long-tracked clipboard stealer to the MyKings (also known as Smominru/DarkCloud) botnet through shared wallets, installers, infrastructure, and batch-script markers. Avast said it had tracked the stealer since 2018, identified more than 6,700 samples, protected over 144,000 users since early 2020, and associated more than 1,300 wallet addresses with over $24.7 million in cryptocurrency transfers.
Unit 42 published analysis of WeSteal, describing it as a Python-based commodity cryptocurrency stealer sold by ComplexCodes and tied to the WeSupply operation. The report noted WeSteal evolved from the earlier WeSupply Crypto Stealer and later added Litecoin, Bitcoin Cash, and Monero support.
The actor ComplexCodes began advertising the WeSteal cryptocurrency clipper on underground forums in mid-February 2021. WeSteal monitored the clipboard and replaced copied wallet addresses with attacker-controlled ones.
Cisco Talos observed renewed Tor2Mine activity between January and June 2020 affecting at least six companies after an apparent hiatus since 2018. The actor expanded beyond XMRig mining to also deploy AZORult, Remcos, DarkVNC, and a clipboard cryptocurrency stealer.
Cisco Talos observed related Tor2Mine activity affecting an environmental consulting company between April and May 2020. The intrusion was part of the actor's broader 2020 resurgence and infrastructure reuse.
Cisco Talos identified eu1[.]ax33y1mph[.]pw as a new Tor2Mine-related domain first seen in March 2020. The finding helped link newly observed infrastructure to the actor's 2020 resurgence.
The Telegram channel "Hack Boss" was created on November 26, 2018 and became the primary distribution point for the HackBoss cryptocurrency-stealing malware family. Avast said the operation pushed fake hacking, cracking, and cryptocurrency tools that actually installed clipboard-hijacking malware and was linked to more than 100 attacker wallet addresses.
In August 2018, Doctor Web analyzed Android.Clipper and added detections for Android.Clipper.1.origin and Android.Clipper.2.origin to its virus databases. The Android malware monitored clipboard wallet numbers and replaced them with attacker-controlled payment addresses.
On February 25, 2018, Proofpoint and Palo Alto Networks Unit 42 observed a malspam campaign targeting users in Japan and the United States that delivered the clipboard-hijacking malware ComboJack. The malware exploited CVE-2017-8579, persisted via a Run key under a fake NVIDIA path, and replaced copied cryptocurrency and payment-system account strings with attacker-controlled destinations.
Kaspersky Lab reported a new CryptoShuffler clipboard-hijacking campaign in June 2017. The malware replaced copied cryptocurrency wallet addresses with attacker-controlled ones, and the operators were reported to have made at least $150,000 from the scheme.
FortiGuard Labs described a multi-stage phishing campaign using a malicious Word document and fake reCAPTCHA to deliver RedLine Clipper, Agent Tesla, and OriginBotnet. The chain established persistence and enabled credential theft, clipboard theft, and cryptocurrency wallet replacement.
AhnLab ASEC discovered a spam email campaign distributing DarkCloud together with a ClipBanker payload. The dropper persisted via the Run key and generated both the infostealer and clipboard wallet-replacement malware from %TEMP%.
Symantec's Threat Hunter Team uncovered a cybercriminal operation using Trojan.Clipminer, malware that combined cryptocurrency mining with clipboard hijacking. Wallet analysis suggested the operators may have earned at least $1.7 million from clipboard hijacking alone.
Cyble Research Labs discovered a TOR website advertising the Eternity Project, a malware suite sold through a Telegram-supported builder. The offering included a clipper, stealer, miner, ransomware, worm, and DDoS bot modules.
Cyble Research Labs discovered malware advertised on a cybercrime forum as 'AvD crypto stealer' and determined it was not a true stealer but a disguised clipper. The payload monitored clipboard contents and replaced cryptocurrency wallet addresses with attacker-controlled ones.
By the time of reporting, the malicious infrastructure used in the dnSpy campaign, including dnSpy[.]net and the fake GitHub repositories, had been taken down. The takedown followed discovery of the malware distribution operation targeting researchers and developers.
Security researchers 0day enthusiast and MalwareHunterTeam discovered a campaign distributing a malicious version of dnSpy through fake GitHub repositories and dnSpy[.]net. The trojanized tool downloaded multiple payloads including Quasar RAT, a clipboard hijacker, and a cryptocurrency miner.
A new information-stealing Trojan named Evrial was reported as being sold on Russian criminal forums for 1,500 rubles and actively distributed. It included clipboard replacement for cryptocurrency addresses and Steam trade URLs to hijack transactions.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 287 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
23 references tracked. Mallory keeps watching after this page renders.
linkedin.com
Open sourcecyfirma.com
Open sourcefortinet.com
Open sourceasec.ahnlab.com
Open sourcebleepingcomputer.com
Open sourcebleepingcomputer.com
Open sourcefireeye.com
Open sourceattack.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.