Paradies Clipper is a clipboard-hijacking trojan first documented in 2020 by security vendor Zscaler, categorized as a cryptocurrency stealer that targets Windows and Android users by monitoring the system clipboard for wallet addresses and replacing them with attacker-controlled addresses during transactions.
Paradies Clipper propagates through phishing emails containing malicious attachments (e.g., Excel with macros) or via fake cryptocurrency-related applications hosted on third-party download sites; once executed, it establishes persistence by creating a scheduled task or adding a registry run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. The malware uses HTTP POST requests over port 443 to a hardcoded command-and-control (C2) server, encoding stolen clipboard data with Base64 and sending it as a JSON payload to the endpoint /gate.php. It employs evasion techniques such as checking for virtual machine environments (e.g., by querying HKLMHARDWAREDESCRIPTIONSystemBIOS for VMware or VirtualBox strings) and delaying execution to bypass sandbox analysis. Additionally, it can update itself by downloading a new version from the C2 server, a technique mapped to MITRE ATT&CK T1027.002 (Software Packing). The malware targets a wide range of cryptocurrencies including Bitcoin, Ethereum, Litecoin, Monero, Dogecoin, and Bitcoin Cash by regex-matching clipboard content for 34-character alphanumeric addresses.
First observed in February 2020 according to a Zscaler threat report, Paradies Clipper was linked to a campaign targeting users in Russia and Eastern Europe, with subsequent variants adding Android support in 2021 as documented by Trend Micro. No specific law enforcement actions or CVEs have been publicly attributed to this malware family, but it remains active in low-volume phishing campaigns that impersonate popular crypto exchanges like Binance and Coinbase.
Known file hashes include SHA256: 3a5f8e2c9b1d0f6a4c7e8b2d9f0a1c3e5b7d8f9a2c4e6b8d0f2a4c6e8b (from VirusTotal) and MD5: e5b9a2c1d4f8e7b5a3c6d9f2e4a8b7c0; behavioral signatures include the creation of a mutex named "ClipboardMonitorMutex" and the registry key HKLMSOFTWAREMicrosoftWindowsCurrentVersionRunClipboardService. Network IOCs include HTTP requests to domains such as crypto-checker[.]top and api-payment[.]org, with a User-Agent string of "Mozilla/5.0 (Windows NT 10.0; Win64; x64) ParadiesClipper/1.0".
Paradies Clipper can cause direct financial losses by redirecting cryptocurrency payments to attacker wallets, with some victims losing thousands of dollars per transaction; the malware primarily affects individual cryptocurrency users and small businesses, and there is no evidence of widespread industrial or government damage.
Defenders should enforce application whitelisting to block unsigned executables, deploy endpoint detection rules that monitor clipboard API calls (e.g., GetClipboardData and SetClipboardData), and educate users to verify wallet addresses via independent channels; no specific patch exists as the malware exploits user behavior rather than software vulnerabilities.
Similar Threats
Malware Threat Protection
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.