Discord Exploited to Spread Clipboard Hijacker Stealing Cryptocurrency Funds
ID: 0af1570d-d673-5690-846e-3f9f8e665b96
STIX ID: report--0af1570d-d673-5690-846e-3f9f8e665b96
Feed Name: GBHackers
CloudSEK's STRIKE team uncovered a targeted campaign by the actor "RedLineCyber" distributing Pro.exe, a PyInstaller-packed Python clipboard-hijacking trojan via Discord social engineering to replace cryptocurrency wallet addresses at paste time and steal funds; the report includes technical behavior (300 ms polling, base64-encoded regex for six crypto formats), persistence details (%APPDATA%\CryptoClipboardGuard), IOCs (two SHA-256s, activity.log path), detection rates, and blockchain evidence of theft.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
