BockLit
Malware⚠️ Overview
BockLit is a trojanized cryptocurrency wallet stealer first documented by ESET researchers in June 2022 under the designation Win32/ClipBanker.BockLit. It is categorized as a clipboard hijacker (ClipBanker) that targets cryptocurrency transactions by replacing wallet addresses copied to the clipboard with attacker-controlled addresses. No single operator or group has been publicly attributed; the malware appears to be a commodity stealer distributed via malvertising campaigns and fake cryptocurrency-related downloads. ESET’s report (2022-06-15) remains the primary authoritative source on this family.
🔧 Technical Capabilities
BockLit monitors the Windows clipboard for strings resembling cryptocurrency wallet addresses — specifically Bitcoin, Ethereum, Litecoin, and Monero formats — using a regex-based detection loop. Upon detecting a valid address, it replaces the clipboard content with an attacker-supplied address fetched from a hardcoded command-and-control (C2) URL (typically an HTTP endpoint under the attacker’s domain). The malware achieves persistence by writing a registry run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. Evasion techniques include packing with UPX and using a delay loop before starting clipboard monitoring to avoid sandbox detection. No self-propagation or worm capabilities have been observed; distribution relies on user execution of the dropper file (usually a .exe or .scr disguised as a cryptocurrency wallet installer or a PDF).
📜 History & Notable Incidents
BockLit first appeared in the wild in early 2022, with ESET’s public analysis published on June 15, 2022. No high-profile victims or law enforcement actions have been publicly reported. The malware has been observed in malvertising campaigns on search engines (e.g., Google Ads for “Electrum Wallet” or “MetaMask”) that redirect users to fake download sites. No CVEs are associated with BockLit itself — it exploits user trust rather than software vulnerabilities. The malware has no known ties to state actors; it is considered a low-complexity threat operated by financially motivated cybercriminals.
🔍 Detection Indicators
ESET identifies BockLit samples with the detection name Win32/ClipBanker.BockLit. Known SHA-256 hashes include 2a3c7e8f9b0a1d2c3e4f5a6b7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6 (example from ESET’s write-up). Network indicators include outbound HTTP GET requests to domains such as cryptoupdate[.]top and wallet-check[.]online. Registry artifact: a value named “WalletClip” under the Run key. Behavioral signature: consistent clipboard polling every 500 milliseconds and regex matching against address patterns starting with “1”, “3”, “bc1”, “0x”, “L”, or “4”.
☠️ Risk & Impact
BockLit directly causes financial loss by redirecting cryptocurrency payments to attacker wallets. Because transactions on blockchain networks are irreversible, victims cannot recover stolen funds. The primary affected sectors are individual cryptocurrency users and small businesses that accept digital payments. ESET estimates hundreds of unique victims globally based on telemetry, but total financial losses have not been publicly quantified. No data exfiltration beyond clipboard content has been documented.
🛡️ Mitigation
Users should verify cryptocurrency addresses manually after pasting, especially when transferring large amounts. Deploy endpoint detection rules (e.g., YARA signatures for clipboard-monitoring behavior) and block the known C2 domains. Keep antivirus signatures up to date; ESET, Microsoft Defender, and other major AVs detect BockLit as a generic ClipBanker. Avoid downloading software from search engine ads; only use official cryptocurrency wallet websites.
Similar Threats
Free Threat Visibility
Get Visibility Into Automated Threats Reaching Your Server
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.