logo

ClipXDaemon Malware Targets Crypto Users in Linux X11 Sessions

ID: 572fdaf4-3c1c-5cf7-87fe-075567e63b27

STIX ID: report--572fdaf4-3c1c-5cf7-87fe-075567e63b27

Feed Name: GBHackers

Threat Score
65/100

Date Published: 2026-03-09

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

ClipXDaemon is a newly observed Linux malware family that targets X11 desktop sessions to hijack cryptocurrency clipboard contents: a three‑stage chain (encrypted bincrypter shell loader -> memory-resident dropper -> on-disk ELF daemon) deploys a 64‑bit X11‑linked daemon that polls the CLIPBOARD, matches wallet address regexes, and replaces copied addresses with attacker-controlled wallets. The implant is persistent at user level (~/.local/bin + ~/.profile), operates entirely offline with encrypted hardcoded replacement addresses (no C2), and attempts light process masquerading; the report includes hashes of loader, dropper, and ELF samples plus multiple wallet IOCs and technical indicators for detection and remediation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.