logo

The long road to your crypto: ClipBanker and its marathon infection chain

ID: 49f5ba61-cd83-5a47-b4e1-49e1d86deac4

STIX ID: report--49f5ba61-cd83-5a47-b4e1-49e1d86deac4

Feed Name: Securelist by Kaspersky

Threat Score
72/100

Date Published: 2026-04-09

Date Updated: 2026-04-29

Author: Oleg Kupreev

...
...

This report describes a multi-stage malware campaign that distributes a trojanized Proxifier installer from GitHub and other pastebin-style hosts; the payload uses Defender exclusions, fileless PowerShell, process injection, and scheduled tasks to ultimately deploy a ClipBanker-style clipboard stealer that replaces cryptocurrency addresses to divert funds. The analysis includes the full execution chain, decoded scripts, replacement addresses, IOCs (URLs and hashes), and notes that more than 2,000 Kaspersky detections occurred since early 2025, mainly in India and Vietnam.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.