logo

Attackers distributing a miner and the ClipBanker Trojan via SourceForge

ID: 204e7dce-51cd-5656-9e3f-5a91fd0a309e

STIX ID: report--204e7dce-51cd-5656-9e3f-5a91fd0a309e

Feed Name: Securelist by Kaspersky

Threat Score
72/100

Date Published: 2025-04-08

Date Updated: 2026-04-29

Author: AMR

...
...

This report describes a criminal campaign that abused SourceForge-generated sourceforge.io subdomains to present fake software downloads that install a large MSI which, through layered archives and scripts, extracts and runs AutoIt-based payloads: a cryptominer and ClipBanker (clipboard‑stealer). The malware performs reconnaissance (Telegram exfil of system info), establishes persistence via services, registry App Paths and WMIC event filters, and provides remote access via an encrypted netcat connection to apap.app:445; telemetry shows ~4,604 affected users (≈90% in Russia).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.