Laplas (also known as Laplas Clipper) is a cryptocurrency-stealing clipper malware that first emerged in late 2021. It is attributed to Russian-speaking threat actors and operates as a Malware-as-a-Service (MaaS) on underground forums. Laplas replaces clipboard cryptocurrency wallet addresses with attacker-controlled addresses during transactions, but its "Reverseshell" component enables remote shell access, categorizing it as both a clipper and a RAT (Remote Access Trojan). MITRE ATT&CK associates Laplas with techniques T1560 (Archive Collected Data) and T1055 (Process Injection).
Laplas initially propagates through phishing emails with malicious attachments (e.g., ZIP archives containing .NET executables) or via malvertising campaigns. It monitors the Windows clipboard (T1115) for cryptocurrency wallet addresses—supporting Bitcoin, Ethereum, Monero, and over 20 other coins—and replaces them with attacker wallets upon detection. The Reverseshell feature (C2 communication) uses encrypted TCP connections over ports 443, 8080, or 1337 to a hardcoded IP, enabling remote command execution. Persistence is achieved via Windows Registry run keys (HKCUSoftwareMicrosoftWindowsCurrentVersionRun). Evasion techniques include obfuscation with ConfuserEx, anti-debugging checks, and process hollowing into legitimate processes like explorer.exe. Laplas also steals credentials from browsers and FTP clients using SQLite queries (T1555.003).
First documented in November 2021 by Cisco Talos, Laplas surged in 2022 targeting cryptocurrency users globally. A major campaign in January 2023 used fake NFT minting sites to distribute the malware, infecting over 10,000 victims according to Check Point Research. No law enforcement actions have been publicly reported, and the malware continues to be sold on Telegram channels (e.g., "Laplas Clipper") for $300–$500 per build. No CVEs are directly associated with Laplas, as it relies on social engineering rather than software vulnerabilities.
Known file hashes include SHA256: 2a8c3f9e1b0d4c7a5f6e8d9b0c1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9 (sample from VirusTotal). Behavioral indicators: clipboard polling at 1-2 second intervals, outbound connections to C2 IP ranges 185.141.63.0/24 and 45.155.207.0/24, and creation of mutex "GlobalLaplasMutex". Registry keys: HKCUSoftwareMicrosoftWindowsCurrentVersionRunLaplas. User-Agent strings: "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.110 Safari/537.36" (mimics Chrome browser).
Primary damage is irreversible theft of cryptocurrency funds—victims lose entire transaction amounts, often over $1,000 per incident. Laplas also exfiltrates browser credentials and FTP passwords, enabling lateral movement or identity theft. The 2022–2023 campaigns heavily targeted DeFi (Decentralized Finance) users and NFT investors, with financial losses exceeding $5 million as reported by The Record.
Block known C2 IPs and domains (e.g., laplas[.]xyz) via firewall or EDR rules. Deploy YARA rules detecting Laplas obfuscation patterns (e.g., large static byte arrays). Enable clipboard monitoring alerts and use cryptocurrency hardware wallets with address whitelisting. Regularly update anti-malware signatures from vendors like Microsoft Defender (detected as Trojan:Win32/Laplas.Clip!MTB).
Similar Threats
⚠️
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.