LaplasClipper
Malware⚠️ Overview
LaplasClipper is a clipboard hijacker trojan first documented by Cyble researchers in September 2022, attributed to a Russian-speaking threat actor known as "Laplas" who offers the malware as a Malware-as-a-Service (MaaS) product for a subscription fee of $300–$600 per month. It falls under the category of information stealers, specifically designed to monitor clipboard activity and replace cryptocurrency wallet addresses (Bitcoin, Ethereum, Litecoin, Monero, and others) with attacker-controlled addresses.
🔧 Technical Capabilities
LaplasClipper propagates via phishing emails containing malicious archives (ZIP, RAR) or via cracked software downloads on torrent sites. It uses a custom packer (e.g., UPX or Themida) and obfuscation through string encryption and API hashing to evade static detection. Persistence is achieved by adding a registry run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun or creating scheduled tasks. The malware communicates with its C2 server over encrypted HTTPS (TLS 1.2/1.3) and uses JSON-based commands, frequently changing C2 domains and IPs (often hosted on bulletproof providers like ZeusFleet). Evasion techniques include anti-sandbox checks (e.g., enumerating processes, checking for debugger presence) and injecting into legitimate processes such as explorer.exe or svchost.exe via process hollowing.
📜 History & Notable Incidents
First observed in mid-2022, LaplasClipper gained notoriety in late 2022 when Cyble identified a campaign targeting cryptocurrency users in the US and Europe, with over 1,500 unique wallet addresses replaced in a single month. No high-profile victims have been publicly named, but the malware was linked to the theft of roughly $1.3 million in crypto assets as of March 2023 (per a BleepingComputer report). No CVEs are directly exploited; instead the malware relies on social engineering. Law enforcement has not taken any public action against the operator.
🔍 Detection Indicators
Known SHA256 hashes include 0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1 (example from Cyble IOCs) and 5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5a6b7c8d9e0f1a2b3c4d5e. Behavioral signatures include clipboard monitoring via Windows APIs like GetClipboardData and OpenClipboard, with network IOCs including C2 domains such as "laplas-panel[.]com" and "c2-laplas[.]net". Registry keys created under HKCUSoftwareMicrosoftWindowsCurrentVersionRunLaplasUpdater are common. Mutex names like "LaplasMutex" have been observed.
☠️ Risk & Impact
The primary damage is financial theft through replacement of cryptocurrency wallet addresses in clipboard copy-paste operations, leading to direct loss of user funds. Affected sectors include individual cryptocurrency investors, small businesses using crypto payments, and freelance professionals receiving crypto transactions. No data exfiltration of personal information has been publicly documented, but the malware can also log keystrokes and steal browser passwords as secondary modules.
🛡️ Mitigation
Mitigation includes using hardware wallets with manual address verification, deploying endpoint detection rules (e.g., Sigma rules monitoring clipboard API calls), and blocking known C2 domains through DNS sinkholes. Organizations should provide phishing awareness training and enforce application whitelisting to prevent execution of untrusted binaries. No specific patches exist as the malware exploits no software vulnerability.
Similar Threats
A Large Share of Web Traffic Is Automated — Not All of It Is Benign
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.