Researchers reported that the Babadeda crypter ecosystem has been used to deliver OpcJacker, a malware family built for credential and cryptocurrency theft. Active since at least the second half of 2022, OpcJacker combines stealer, keylogger, clipper, and loader functions, harvesting browser data, monitoring clipboard activity, and replacing copied wallet addresses to divert cryptocurrency transactions. The malware also establishes persistence and can deploy follow-on payloads including NetSupport RAT and a modified hVNC variant.
The campaigns relied on fake software distribution and malvertising, including a geofenced operation impersonating a legitimate VPN service and serving malicious archives from compromised websites. Trend Micro said the malware is loaded through a DLL side-loading chain tied to Babadeda and uses a custom virtual-machine-like configuration format designed to complicate analysis. Separate reporting linked Babadeda activity to targeting of crypto, NFT, and DeFi communities, while the same loader ecosystem has also shown overlap with Phobos Crypter activity and delivery of Phobos ransomware.

Pull IOCs and campaign context straight into your stack.
3 events from the most recent confirmed update back to the earliest known activity.
In February 2023, attackers used geofenced malvertisements targeting users in Iran to impersonate a legitimate VPN service and deliver malicious archives carrying OpcJacker. The campaign used compromised websites and checked victim IP addresses before serving the malware.
Trend Micro reported that the newly identified OpcJacker malware family had been active since the second half of 2022. The malware combined stealer, keylogger, clipper, and loader capabilities with a focus on cryptocurrency theft.
Trend Micro published research describing OpcJacker as a distinct malware family, detailing its VM-like configuration format, DLL side-loading chain, cryptocurrency clipboard hijacking, and links to the Babadeda crypter ecosystem. The report also noted overlap with activity described as Phobos Crypter and delivery associated with Phobos ransomware.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.