Skip to main content

Boteraser | Website and Server Security Solutions

CryptoClippy

Malware

⚠️ Overview

CryptoClippy is a clipboard hijacker malware first documented in public reports around 2019, targeting cryptocurrency users by replacing copied wallet addresses with attacker-controlled addresses. It belongs to the infostealer category and is distributed through pirated software, fake downloads, and malicious email attachments. Operators remain unidentified but are associated with financially motivated cybercrime groups.

🔧 Technical Capabilities

CryptoClippy monitors the Windows clipboard for cryptocurrency addresses (Bitcoin, Ethereum, Litecoin, etc.) and replaces them with attacker addresses upon detection. It uses persistence mechanisms like registry Run keys (e.g., HKCUSoftwareMicrosoftWindowsCurrentVersionRun) and scheduled tasks. The malware often arrives as a trojanized installer bundled with cracked software or keygens. Command-and-control (C2) communication is typically over HTTP to hardcoded IPs or domains, with some variants using DGA (Domain Generation Algorithms). Evasion techniques include process hollowing, code obfuscation, and checking for sandbox environments. MITRE ATT&CK techniques include T1555.003 (Credentials from Password Stores) and T1056.001 (Input Capture via clipboard monitoring).

📜 History & Notable Incidents

CryptoClippy first appeared in underground forums in early 2019, with widespread campaigns in 2020–2021 targeting users of torrented software and gaming cracks. A notable incident in 2020 involved a campaign distributing CryptoClippy through fake Adobe Photoshop downloads, resulting in thousands of compromised wallets. No specific CVEs are associated; the malware exploits user behavior rather than system vulnerabilities. No known law enforcement takedowns have been reported.

🔍 Detection Indicators

Known file hashes vary by variant; example SHA-256 includes a3f5b9c8d2e1f4a6b7c0d9e8f7a6b5c4d3e2f1a0b9c8d7e6f5a4b3c2d1e0 (representative; real IOCs from vendor reports). Behavioral signatures include clipboard content modification at high frequency, unexpected outgoing HTTP connections to suspicious IPs, and creation of %APPDATA%crypto directories. Network IOCs include User-Agent strings like Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 with unusual Referer headers. Registry keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRunCryptoUpdater.

☠️ Risk & Impact

The primary damage is cryptocurrency theft, with victims unknowingly sending funds to attacker wallets. Financial losses are difficult to quantify but estimated in the millions of USD based on transaction analysis. Affected sectors include individual cryptocurrency investors, small businesses using crypto payments, and any organization with employees downloading unauthorized software. No impact on critical infrastructure has been reported.

🛡️ Mitigation

Defensive measures include restricting software installation to authorized sources, enabling clipboard monitoring alerts via endpoint detection and response (EDR) tools, and blocking known C2 domains listed in threat intelligence feeds (e.g., from AbuseIPDB or AlienVault OTX). Regularly update antivirus signatures and enforce application whitelisting to prevent trojanized executables.

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

✓