logo

HUMINT Operations Uncover Cryptojacking Campaign: Discord-Based Distribution of Clipboard Hijacking Malware Targeting Cryptocurrency Communities

ID: 06275be7-91d5-5aeb-934d-53c3acc1210a

STIX ID: report--06275be7-91d5-5aeb-934d-53c3acc1210a

Feed Name: CloudSEK Blog

Threat Score
70/100

Date Published: 2026-01-15

Date Updated: 2026-04-27

...
...

**Executive Summary:** CloudSEK's STRIKE team exposed a Python-based clipboard hijacker (distributed as Pro.exe/peeek.exe) operated by an actor self-styled 'RedLineCyber' that targets cryptocurrency streamers and gaming/gambling Discord communities by social engineering, installs persistence, monitors clipboard contents at ~300ms intervals, and substitutes victim wallet addresses with attacker-controlled addresses across six cryptocurrencies; the report provides static/dynamic analysis, IOCs (SHA-256 hashes, registry run key, attacker wallets), MITRE mapping, detection rules, and mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.