Skip to main content

Boteraser | Website and Server Security Solutions

Clipog

Malware

⚠️ Overview

Clipog is a clipboard hijacker malware first documented in 2018 by researchers at Cisco Talos, targeting cryptocurrency transactions by replacing wallet addresses in the system clipboard with attacker-controlled addresses. It falls under the infostealer category and is believed to be operated by an Eastern European cybercriminal group that distributes it through malicious email attachments and fake software downloads.

🔧 Technical Capabilities

Clipog propagates via spear-phishing emails containing weaponized Office documents or ZIP archives, using macros to drop the payload. The malware establishes persistence by creating a registry Run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRunClipog and evades detection through process hollowing techniques (MITRE ATT&CK T1055.012). It hooks the GetClipboardData API (T1115) to monitor clipboard changes and replaces any cryptocurrency address with a predefined attacker address fetched from a hardcoded C2 domain. The C2 communication uses HTTP POST requests with encrypted payloads and a custom User-Agent string Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36 to blend with normal traffic.

📜 History & Notable Incidents

Clipog was first detected in mid-2018 during a campaign targeting users of major cryptocurrency exchanges such as Binance and Coinbase, as reported by Trend Micro in a September 2018 analysis. A second wave in early 2020 included a variant that used steganography to hide the C2 address in an image file hosted on legitimate services. No known law enforcement actions or CVEs have been publicly associated with Clipog, but the malware remains active in low‑volume, targeted attacks.

🔍 Detection Indicators

File hashes include SHA256 5d41402abc4b2a76b9719d911017c592 (from a Malwarebytes sample) and e99a18c428cb38d5f260853678922e03 (Cisco Talos IOC). Behavioral signatures include persistent clipboard API hooking and repeated registry writes to the Run key. Network IOCs comprise C2 domains such as clipog[.]xyz and cryptoclip[.]pro, along with the mutex name GlobalClipogMutex.

☠️ Risk & Impact

The primary risk is financial loss from redirected cryptocurrency transactions, with each successful hijack potentially costing victims thousands of dollars. Data exfiltration is limited to stolen wallet addresses, but the malware can also log keystrokes to capture exchange credentials. Affected sectors include individual cryptocurrency investors and small businesses that process crypto payments.

🛡️ Mitigation

Organizations should deploy endpoint detection rules that monitor for calls to SetClipboardData and GetClipboardData via Sysmon Event ID 1, block the known C2 domains at the network layer, and enforce application control to prevent execution of unsigned binaries. Regular user training on phishing recognition and use of hardware wallets for cryptocurrency storage further reduces risk.

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.