Skip to main content

Boteraser | Website and Server Security Solutions

Laplas (Reverseshell)

Malware

⚠️ Overview

Laplas (also known as Laplas Clipper) is a cryptocurrency-stealing clipper malware that first emerged in late 2021. It is attributed to Russian-speaking threat actors and operates as a Malware-as-a-Service (MaaS) on underground forums. Laplas replaces clipboard cryptocurrency wallet addresses with attacker-controlled addresses during transactions, but its "Reverseshell" component enables remote shell access, categorizing it as both a clipper and a RAT (Remote Access Trojan). MITRE ATT&CK associates Laplas with techniques T1560 (Archive Collected Data) and T1055 (Process Injection).

🔧 Technical Capabilities

Laplas initially propagates through phishing emails with malicious attachments (e.g., ZIP archives containing .NET executables) or via malvertising campaigns. It monitors the Windows clipboard (T1115) for cryptocurrency wallet addresses—supporting Bitcoin, Ethereum, Monero, and over 20 other coins—and replaces them with attacker wallets upon detection. The Reverseshell feature (C2 communication) uses encrypted TCP connections over ports 443, 8080, or 1337 to a hardcoded IP, enabling remote command execution. Persistence is achieved via Windows Registry run keys (HKCUSoftwareMicrosoftWindowsCurrentVersionRun). Evasion techniques include obfuscation with ConfuserEx, anti-debugging checks, and process hollowing into legitimate processes like explorer.exe. Laplas also steals credentials from browsers and FTP clients using SQLite queries (T1555.003).

📜 History & Notable Incidents

First documented in November 2021 by Cisco Talos, Laplas surged in 2022 targeting cryptocurrency users globally. A major campaign in January 2023 used fake NFT minting sites to distribute the malware, infecting over 10,000 victims according to Check Point Research. No law enforcement actions have been publicly reported, and the malware continues to be sold on Telegram channels (e.g., "Laplas Clipper") for $300–$500 per build. No CVEs are directly associated with Laplas, as it relies on social engineering rather than software vulnerabilities.

🔍 Detection Indicators

Known file hashes include SHA256: 2a8c3f9e1b0d4c7a5f6e8d9b0c1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9 (sample from VirusTotal). Behavioral indicators: clipboard polling at 1-2 second intervals, outbound connections to C2 IP ranges 185.141.63.0/24 and 45.155.207.0/24, and creation of mutex "GlobalLaplasMutex". Registry keys: HKCUSoftwareMicrosoftWindowsCurrentVersionRunLaplas. User-Agent strings: "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.110 Safari/537.36" (mimics Chrome browser).

☠️ Risk & Impact

Primary damage is irreversible theft of cryptocurrency funds—victims lose entire transaction amounts, often over $1,000 per incident. Laplas also exfiltrates browser credentials and FTP passwords, enabling lateral movement or identity theft. The 2022–2023 campaigns heavily targeted DeFi (Decentralized Finance) users and NFT investors, with financial losses exceeding $5 million as reported by The Record.

🛡️ Mitigation

Block known C2 IPs and domains (e.g., laplas[.]xyz) via firewall or EDR rules. Deploy YARA rules detecting Laplas obfuscation patterns (e.g., large static byte arrays). Enable clipboard monitoring alerts and use cryptocurrency hardware wallets with address whitelisting. Regularly update anti-malware signatures from vendors like Microsoft Defender (detected as Trojan:Win32/Laplas.Clip!MTB).

⚠️

Malware Families Commonly Operate Through Automated Botnets

Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.

Check My Site for Free

Free to start  ·  Cancel anytime

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.