logo

Hackers Distribute ClipBanker Malware via Fake Proxifier Installer On GitHub

ID: df976987-16d0-576b-a275-99760ab35bff

STIX ID: report--df976987-16d0-576b-a275-99760ab35bff

Feed Name: Cyber Press

Threat Score
75/100

Date Published: 2026-04-14

Date Updated: 2026-04-14

Author: Varshini

...
...

### Executive summary A malicious GitHub repository masquerading as the Proxifier proxy utility delivers a trojanized installer that performs multiple evasive steps (temporary donor processes, Defender exclusion additions, injected .NET modules, obfuscated PowerShell stored in the registry, and scheduled tasks) to persist and fetch follow-on payloads; the final in-memory payload is ClipBanker, a C++ clipboard hijacker that replaces many cryptocurrency wallet addresses with attacker-controlled ones, and researchers observed over 2,000 detections largely in India and Vietnam.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.