logo

The Fake “RedLine”: Imposter Malware Hijacks Crypto Wallets on Discord

ID: bd6b8425-8476-51e4-89b0-b859903c46c3

STIX ID: report--bd6b8425-8476-51e4-89b0-b859903c46c3

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-01-19

Date Updated: 2026-04-23

Author: Ddos

...
...

CloudSEK STRIKE uncovered "RedLineCyber," a cybercrime campaign posing as an affiliate of the RedLine infostealer family to distribute a stealthy Python clipboard hijacker via private Discord communities; the malware monitors the Windows clipboard and replaces cryptocurrency addresses (Bitcoin, Ethereum, Solana, Dogecoin, Litecoin, Tron) with attacker-controlled addresses, enabling silent theft from streamers and community members through prolonged social engineering.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.