The Fake “RedLine”: Imposter Malware Hijacks Crypto Wallets on Discord
ID: bd6b8425-8476-51e4-89b0-b859903c46c3
STIX ID: report--bd6b8425-8476-51e4-89b0-b859903c46c3
Feed Name: securityonline.info
Threat Score
CloudSEK STRIKE uncovered "RedLineCyber," a cybercrime campaign posing as an affiliate of the RedLine infostealer family to distribute a stealthy Python clipboard hijacker via private Discord communities; the malware monitors the Windows clipboard and replaces cryptocurrency addresses (Bitcoin, Ethereum, Solana, Dogecoin, Litecoin, Tron) with attacker-controlled addresses, enabling silent theft from streamers and community members through prolonged social engineering.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
