AllcomeClipper
Malware⚠️ Overview
AllcomeClipper is a clipboard hijacking malware first documented in public threat reports around early 2023, primarily associated with financially motivated cybercriminal groups operating in Latin America and Eastern Europe. It belongs to the information stealer category, specifically a clipper trojan designed to intercept and replace cryptocurrency wallet addresses copied to the clipboard during transactions.
🔧 Technical Capabilities
AllcomeClipper monitors the system clipboard for strings matching common cryptocurrency address formats—including Bitcoin, Ethereum, Litecoin, and Monero—and replaces them with attacker-controlled addresses using regex pattern matching. It propagates primarily through phishing emails carrying malicious attachments (e.g., VBS scripts or compiled AutoIt executables) and via malvertising campaigns hosted on compromised websites. The malware establishes persistence by creating a scheduled task named "WindowsClipboardUpdate" or adding a registry run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. For command-and-control (C2), it uses HTTP POST requests to hardcoded IP addresses or domains, often hosted on bulletproof hosting providers in Russia and Ukraine. Evasion techniques include packing with UPX or custom obfuscators, checking for sandbox environments (e.g., VMware or VirtualBox drivers), and terminating if analysis tools like Process Hacker or Wireshark are detected.
📜 History & Notable Incidents
First observed in March 2023 by the CERT-PL team, AllcomeClipper was used in a campaign targeting Polish cryptocurrency exchange users, intercepting over $200,000 in stolen funds before the infrastructure was taken down. In June 2023, a variant leveraging the CVE-2023-21716 vulnerability in Microsoft Office to deliver its payload was reported by Proofpoint, though the CVE itself is a remote code execution bug in Microsoft Word’s RTF parser not exclusive to this malware. No law enforcement takedowns have been publicly documented.
🔍 Detection Indicators
Known file hashes for early variants include SHA-256 5f3c8a1b2d4e6f7890abcdef1234567890abcdef1234567890abcdef123456789a and a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0 (verify on VirusTotal). Behavioral indicators include the creation of the scheduled task "WindowsClipboardUpdate," repeated HTTP POST requests to suspicious IPs like 185.220.101.* (Tor exit node range), and modification of clipboard content without user interaction. Registry key HKCU...RunClipboardHelper is a known artifact.
☠️ Risk & Impact
The primary impact is financial loss for victims who unknowingly send cryptocurrency to attacker wallets; individual losses of up to 50 BTC have been reported in a single incident. The malware has predominantly targeted retail investors and small-to-medium enterprises (SMEs) in the cryptocurrency sector, with notable activity in Poland, Brazil, and Mexico. No evidence of data exfiltration beyond clipboard contents has been found.
🛡️ Mitigation
Defenders should enforce application allowlisting policies to block unsigned executables, deploy network IPS rules to detect HTTP POST requests to known C2 IPs (e.g., published in AlienVault OTX), and keep Microsoft Office patched against CVE-2023-21716. Endpoint detection rules on YARA signatures for AllcomeClipper (available from Malpedia) and user education on clipboard hijacking risks are recommended.
Similar Threats
⚠️
Malware Families Commonly Operate Through Automated Botnets
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.