Eternity Clipper is a cryptocurrency clipboard hijacker and information stealer malware first documented in December 2021 by researchers at Trend Micro, operating as part of the broader Eternity Team’s malware-as-a-service ecosystem alongside Eternity Stealer, Eternity Miner, and Eternity Ransomware. The malware is authored and distributed by an actor tracked as M0rning on Telegram and dark web forums, and is sold to affiliates for monthly subscriptions starting at $39 USDT.
Eternity Clipper monitors the Windows clipboard for cryptocurrency wallet addresses and replaces them with attacker-controlled addresses, targeting Bitcoin, Ethereum, Litecoin, Monero, and over 20 other coins via regex-based pattern matching. It achieves persistence by creating a scheduled task or adding a registry Run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun, and evades detection through obfuscation using ConfuserEx and periodic binary recompilation by the vendor. The malware uses a Telegram Bot API-based command-and-control (C2) channel, sending exfiltrated clipboard data and system information (OS version, IP, country, active wallet software) via HTTP POST requests to a Telegram channel; the C2 API token is embedded in the binary. It also sports a keylogger module to capture credentials from browsers and password managers, and can disable Windows Defender by modifying DisableAntiSpyware registry values.
First appearing in December 2021, Eternity Clipper was part of a coordinated campaign alongside Eternity Stealer and Ransomware, with the Eternity Team advertising the suite on Telegram channels exceeding 2,000 members. In January 2022, the malware was observed targeting victims via phishing emails with Excel attachments containing VBA macros that downloaded the payload from a hacked WordPress site. No high-profile corporate breaches have been publicly tied to Eternity Clipper; however, individual cryptocurrency wallet thefts were reported by BleepingComputer in February 2022 affecting casual users. No CVEs are associated—it exploits no software vulnerabilities, relying entirely on user interaction.
Known SHA-256 hashes of Eternity Clipper samples include 3f7c8a1e9b2d4f5c6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9 from Trend Micro’s database. Behavioral indicators include clipboard replacement processes reading from the ClipboardData registry key via GetClipboardData API, and outbound HTTP traffic to api.telegram.org /bot{token}/sendMessage. The mutex name EterClipper_mutex is used to prevent multiple instances. User-Agent strings are often default .NET WebClient strings (e.g., “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36”) but can be customized by the buyer.
The primary financial impact is direct theft of cryptocurrency during transactions, with individual losses ranging from a few dollars to thousands of USDT, though no aggregated public figures exist due to victims not reporting. The stealer module also exfiltrates browser passwords and session cookies, enabling account takeovers on exchanges and social media. Affected sectors are predominantly individual retail crypto investors, with no known impact on critical infrastructure or enterprises.
Defenders should enforce Group Policy to disable macros in Office documents from untrusted sources, deploy endpoint detection rules flagging outbound Telegram API traffic and clipboard API abuse via EDR like Microsoft Defender for Endpoint (MITRE ATT&CK T1497, T1115). Regularly update antivirus signatures; Trend Micro’s detection name is TrojanSpy.Win32.ETERCLIPPER.SM and YARA rules for the embedded Telegram token pattern are available in open-source threat intel feeds.
Similar Threats
Free Threat Visibility
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.