logo

Fake Proxifier GitHub Installer Spreads ClipBanker Crypto Malware

ID: 383f6284-d479-5786-8082-6db7d105881f

STIX ID: report--383f6284-d479-5786-8082-6db7d105881f

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-04-14

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

Attackers distributed a trojanized Proxifier installer on GitHub to deliver a fileless, multi-stage ClipBanker campaign that weakens Microsoft Defender, runs obfuscated PowerShell from registry and scheduled tasks, injects shellcode into legitimate processes, and continually monitors and replaces cryptocurrency wallet addresses to redirect funds; Kaspersky observed over 2,000 detections primarily in India and Vietnam.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.