logo

Discord Exploited to Spread Clipboard Hijacker Stealing Cryptocurrency Funds

ID: 0af1570d-d673-5690-846e-3f9f8e665b96

STIX ID: report--0af1570d-d673-5690-846e-3f9f8e665b96

Feed Name: GBHackers

Threat Score
70/100

Date Published: 2026-01-20

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

CloudSEK's STRIKE team uncovered a targeted campaign by the actor "RedLineCyber" distributing Pro.exe, a PyInstaller-packed Python clipboard-hijacking trojan via Discord social engineering to replace cryptocurrency wallet addresses at paste time and steal funds; the report includes technical behavior (300 ms polling, base64-encoded regex for six crypto formats), persistence details (%APPDATA%\CryptoClipboardGuard), IOCs (two SHA-256s, activity.log path), detection rates, and blockchain evidence of theft.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.