Crypto Clipper - What is It?

31181472875?profile=RESIZE_400xCrypto Clipper is a trojan deployed via USB storage devices that has been affecting users since February 2026.  It looks for clipboard data and other valuable assets, predominately associated with Crypto wallet addresses, and exfiltrates this information with Clipper malware.

It does this through a bundled Tor proxy, using Windows Script host and ActiveX logic, to connect to a hidden C2 server, carrying out high frequency clipboard theft, collecting screenshots, and running crypto wallet address substitution.  Unlike most malware, this does not depend on an installer or exposed IP-based C2 infrastructure.  It deploys a portable Tor client, routes traffic through a SOCKS5 proxy and mixes data exfiltration with remote code execution.

ATTACK CHAIN

31181472489?profile=RESIZE_584xThis particular malware is made of two components.  A worm to ensure propagation and a clipper component to steal valuable information.  The worm works by creating additional malicious shortcut links of legitimate files found on the device.  It delivers file-based payloads and excludes them from Windows Defender scanning.  In addition, the worm component deploys scheduled tasks for execution and persistence for both components.

The clipper runs script-based payloads to interact with the Operating system through WScript and ActiveXObject.  It runs anti-analysis checks that look for running processes and exits if Task Manager is detected.  Otherwise, the clipper launches a tor binary, ugate.exe, waits for Tor to bootstrap, generates a victim GUID, and registers the infected device with the hidden service C2 server.

BEHAVIOR AND METHODS - The initial access for this malware occurs from malicious .lnk files distributed from USB storage devices, according to the Microsoft Defender Security Research Team.  This .lnk payload will search for common document files, such as .doc or .pdf, hide these files, and replace them with the .lnk files of the same name.  When clicked, these shortcut files fetch the worm payload from the C2 server through Tor, without alerting the end user.

As the worm payload runs, it excludes staging folders and Windows binaries used in the stealer component execution to avoid detection.  The malware will then drop decrypted payloads, including two malicious JS files in the `C:\Users\Public\Documents` folder.  Additionally, this worm component will create two scheduled tasks. One to insert itself onto any uncompromised USB storage disks inserted in the future. And another for the clipper activity.

C2 FUNCTIONALITY - When the clipper is active, it connects to the C2 server over a Tor-routed domain, through the localhost on port 9050.  This helps obscure the final c2 destination, complicated destination-based blocking.  It also helps keep anonymity for the malicious actor while keeping the malware compact.

The C2 has three endpoints. Route.php for beacon and command retrieval, recvf.php for file uploads, and stub.php for the initial payload download.  The C2 can receive different actions from the malware, receiving information concerning the victim GUID, stolen seed phrases, stolen private keys, and notice of address replacement.  Lastly, the C2 can deliver the command GUID or EVAL.  The GUID command will acknowledge receipt of the victim GUID or request a refresh.  The EVAL command will allow for the remote execution of additional JavaScript code.

COLLECTION - The clipper focuses on high-value financial assets.  It detects all 12 or 24-word BIP39 phrases in the clipboard data.  It will save these seeds to a local file as a backup and send it to the C2 domain via Tor.  It retries until receipt is acknowledged, then deletes the local backup. It will also take five screenshots and upload those as well, giving the threat actor additional context on the victim’s wallets and balances.

Another functionality the crypto clipper has is to detect cryptocurrency addresses, replacing them with attacker controlled addresses, so any copy and paste cryptocurrency payments will be received by the attacker rather than the intended recipient.

DETECTION AND PROTECTION - To detect this malware, you may need to look for any script interpreters spawning suspicious child processes.  Monitor your device for any localhost:9050 proxy usage.  Identify screen-capture commands running in PowerShell.  Monitor for signs of clipboard inspection, or watch for any instances of crypto wallet address replacement.

To protect against this malware, disable autorun or autoplay options for removable media. Block ‘.lnk’ execution from removable drives.  Restrict unnecessary use of wscript, cscript and similar.  Investigate script-to-network chains involving Curl, PowerShell or CMD.exe.  Monitor for any SOCKS5 proxy activity.  And lastly, review any clipboard and screen capture behaviors.

Source: MSN

This article is shared at no charge for educational and informational purposes only.

Red Sky Alliance is a Cyber Threat Analysis and Intelligence Service organization.  We provide indicators of compromise information (CTI) via a notification/Tier I analysis service (RedXray) or an analysis service (CTAC).  For questions, comments or assistance, please contact the office directly at 1-844-492-7225, or feedback@redskyalliance.com    

Weekly Cyber Intelligence Briefings:

Weekly Cyber Intelligence Briefings:

REDSHORTS - Weekly Cyber Intelligence Briefings

https://attendee.gotowebinar.com/register/7855487668891299929

E-mail me when people leave their comments –

You need to be a member of Red Sky Alliance to add comments!