A malicious Android app posing as MetaMask was discovered on Google Play, marking the first reported case of clipper malware identified in the official Android app store. ESET detected the app as Android/Clipper.C and found that it targeted users looking for a mobile version of MetaMask, even though MetaMask at the time was available only as browser extensions for Chrome and Firefox.
The malware was built to steal Ethereum wallet credentials and private keys, and it could also monitor the clipboard and replace copied Bitcoin or Ethereum wallet addresses with attacker-controlled addresses to redirect cryptocurrency payments. According to ESET, the malicious package was uploaded to Google Play on February 1 and was removed after the company notified Google’s security team.

Pull IOCs and campaign context straight into your stack.
5 events from the most recent confirmed update back to the earliest known activity.
In February 2019, ESET researchers discovered what the source describes as the first reported clipper malware on the official Google Play store. The campaign targeted users looking for a nonexistent mobile MetaMask app.
A malicious app package named com.lemon.metamask, detected by ESET as Android/Clipper.C, was introduced to Google Play while impersonating MetaMask. It was designed to steal Ethereum wallet credentials and private keys and to replace copied cryptocurrency wallet addresses with attacker-controlled ones.
The source says Android clipper malware had previously been observed in shady Android app stores in 2018, predating its discovery in Google Play.
The source states that clipper malware first appeared on Windows in 2017, providing background on the malware family before its appearance on Android and Google Play.
After ESET notified Google's security team about the fake MetaMask clipper app, Google removed it from the Play Store. The source does not provide a specific date for the removal.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.