HUMINT Operations Uncover Cryptojacking Campaign: Discord-Based Distribution of Clipboard Hijacking Malware Targeting Cryptocurrency Communities
ID: 06275be7-91d5-5aeb-934d-53c3acc1210a
STIX ID: report--06275be7-91d5-5aeb-934d-53c3acc1210a
Feed Name: CloudSEK Blog
**Executive Summary:** CloudSEK's STRIKE team exposed a Python-based clipboard hijacker (distributed as Pro.exe/peeek.exe) operated by an actor self-styled 'RedLineCyber' that targets cryptocurrency streamers and gaming/gambling Discord communities by social engineering, installs persistence, monitors clipboard contents at ~300ms intervals, and substitutes victim wallet addresses with attacker-controlled addresses across six cryptocurrencies; the report provides static/dynamic analysis, IOCs (SHA-256 hashes, registry run key, attacker wallets), MITRE mapping, detection rules, and mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
