The long road to your crypto: ClipBanker and its marathon infection chain
ID: 49f5ba61-cd83-5a47-b4e1-49e1d86deac4
STIX ID: report--49f5ba61-cd83-5a47-b4e1-49e1d86deac4
Feed Name: Securelist by Kaspersky
This report describes a multi-stage malware campaign that distributes a trojanized Proxifier installer from GitHub and other pastebin-style hosts; the payload uses Defender exclusions, fileless PowerShell, process injection, and scheduled tasks to ultimately deploy a ClipBanker-style clipboard stealer that replaces cryptocurrency addresses to divert funds. The analysis includes the full execution chain, decoded scripts, replacement addresses, IOCs (URLs and hashes), and notes that more than 2,000 Kaspersky detections occurred since early 2025, mainly in India and Vietnam.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
