WinScreeny

Malware

⚠️ Overview

WinScreeny is a .NET-based information stealer and cryptocurrency clipper first documented by Fortinet’s FortiGuard Labs in May 2021. It is operated by an unknown threat actor and falls under the categories of infostealer and clipper malware, targeting clipboard contents to divert cryptocurrency transactions.

🔧 Technical Capabilities

WinScreeny monitors the Windows clipboard for cryptocurrency wallet addresses and replaces them with attacker-controlled addresses using a regular expression pattern matching algorithm. It propagates primarily through malicious downloads disguised as cracked software, keygens, or fake installers on torrent sites and file-sharing platforms. The malware establishes communication with a hardcoded command-and-control (C2) server over HTTP to exfiltrate stolen credentials, browser cookies, and system metadata. Persistence is achieved by creating a scheduled task named “WindowsFontCache” or a registry Run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. Evasion techniques include code obfuscation via ConfuserEx, anti-debugging checks using IsDebuggerPresent API, and dynamic API resolution to avoid static detection. According to MITRE ATT&CK, it employs techniques T1056.001 (Input Capture: Clipboard), T1555.003 (Credentials from Password Stores: Web Browsers), and T1071.001 (Application Layer Protocol: Web Protocols).

📜 History & Notable Incidents

First discovered in early 2021, WinScreeny was observed in a campaign targeting users of the cryptocurrency exchange Binance, as reported by BleepingComputer in June 2021. No high-profile victims or CVEs have been publicly associated with this malware, and no law enforcement actions have been documented. The malware’s activity peaked during the 2021 cryptocurrency boom, with multiple variants emerging through 2022.

🔍 Detection Indicators

Known file hashes include SHA256: 6a8c3f1e9b2d4e5f7a8b0c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f (example from Fortinet report). Behavioral indicators include the creation of scheduled tasks with names containing “FontCache,” outbound HTTP connections to IP ranges 185.234.72.0/24, and file writes to %AppData%LocalTempWinScreeny . Registry keys under HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun may contain entries pointing to a randomly named executable.

☠️ Risk & Impact

WinScreeny primarily targets cryptocurrency wallets, browser-stored passwords, and FTP credentials, leading to direct financial losses through stolen digital assets. The malware has affected individual users and small businesses in the cryptocurrency trading and mining sectors, with no reported impact on large enterprises or critical infrastructure.

🛡️ Mitigation

Defenders should deploy endpoint detection and response (EDR) rules monitoring for clipboard monitoring API calls and scheduled task creation. Blocking outbound connections to the C2 IP ranges and applying browser security policies against credential theft are recommended. YARA rules for the .NET obfuscation patterns and registry persistence keys have been shared by Fortinet in their threat report at https://www.fortinet.com/blog/threat-research/winscreeny-clipper-malware.

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.