logo

Hackers Use Fake Proxifier Installer on GitHub to Spread ClipBanker Crypto-Stealing Malware

ID: 8e7696fc-e820-5594-bac1-4269e85905d0

STIX ID: report--8e7696fc-e820-5594-bac1-4269e85905d0

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-04-14

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A multi-stage ClipBanker malware campaign has been distributing a trojanized Proxifier installer via a fake GitHub repository that appears legitimate; once executed it deploys a stealthy infection chain (Defender exclusions, process injection, fileless PowerShell, registry-stored payload and a scheduled task) and watches the clipboard to replace cryptocurrency wallet addresses across 26+ blockchains, resulting in reported infections (over 2,000 Kaspersky detections since early 2025), mainly affecting users in India and Vietnam.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.