Attackers distributing a miner and the ClipBanker Trojan via SourceForge
ID: 204e7dce-51cd-5656-9e3f-5a91fd0a309e
STIX ID: report--204e7dce-51cd-5656-9e3f-5a91fd0a309e
Feed Name: Securelist by Kaspersky
This report describes a criminal campaign that abused SourceForge-generated sourceforge.io subdomains to present fake software downloads that install a large MSI which, through layered archives and scripts, extracts and runs AutoIt-based payloads: a cryptominer and ClipBanker (clipboard‑stealer). The malware performs reconnaissance (Telegram exfil of system info), establishes persistence via services, registry App Paths and WMIC event filters, and provides remote access via an encrypted netcat connection to apap.app:445; telemetry shows ~4,604 affected users (≈90% in Russia).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
