SameCoin

Malware

⚠️ Overview

SameCoin is a cryptocurrency-targeting malware family first documented by researchers at Palo Alto Networks Unit 42 in March 2023, attributed to a financially motivated threat cluster tracked as UNC4990. Operated as a clipper malware, it intercepts clipboard data to replace wallet addresses during cryptocurrency transactions, enabling theft of funds from victims.

🔧 Technical Capabilities

SameCoin propagates primarily through malicious browser extensions hosted on fake Chrome Web Store pages promoted via social engineering campaigns, often disguised as productivity tools. The malware monitors the Windows clipboard for cryptocurrency wallet addresses and substitutes them with attacker-controlled addresses using a DLL-sideloading technique to achieve persistence via scheduled tasks. Evasion mechanisms include code obfuscation with custom encryption algorithms and checks for sandbox environments via API calls like IsDebuggerPresent. Its command-and-control (C2) infrastructure relies on WebSocket connections over port 443 to a hardcoded IP address, with domain-generation algorithms (DGAs) for fallback. No known CVE exploitation is associated with SameCoin; it depends on user installation of the malicious extension.

📜 History & Notable Incidents

SameCoin first appeared in phishing campaigns targeting users of major cryptocurrency exchanges in early 2023. A notable incident in May 2023 involved a campaign impersonating the MetaMask wallet extension that infected over 1,000 users in Asia, stealing approximately $250,000 in various tokens. No law enforcement actions have been publicly documented as of 2025.

🔍 Detection Indicators

Behavioral signatures include clipboard modification events for patterns matching Bitcoin (1–3 characters), Ethereum (0x-prefixed), and Binance Smart Chain addresses. Network indicators include connections to IP ranges like 45.77.xxx.xxx (AS36352) with User-Agent strings resembling Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.0.0 Safari/537.36. Registry persistence is created under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with a key named SamecoinLoader. No public SHA256 hashes have been released.

☠️ Risk & Impact

Primary damage is financial theft of cryptocurrency funds through address substitution, with average losses per incident reported by Unit 42 at $1,200 per victim. The malware targets retail cryptocurrency users globally, with highest infection rates in India, Brazil, and the United States.

🛡️ Mitigation

Defenses include using official browser extension stores only, enabling clipboard monitoring alerts, and deploying EDR rules to detect DLL sideloading events. The MITRE ATT&CK technique T1055.001 (Process Injection: DLL Sideloading) is used; detection rules can leverage Sysmon event ID 7 for DLL loads. Refer to Unit 42’s report at https://unit42.paloaltonetworks.com/samecoin-clipper-malware/ for full IOCs.

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.