Clipper Malware Targets IBAN & Crypto Transactions
ID: b93722b1-038b-5a1d-aed6-f7ccae23768a
STIX ID: report--b93722b1-038b-5a1d-aed6-f7ccae23768a
Feed Name: Cyble Blog
This report describes underground cybercriminal activity involving IBAN clipper malware sold as subscription services on forums; the malware monitors clipboard content, detects IBANs via regex, and replaces recipient IBANs with attacker-controlled accounts to divert SEPA transfers. The report also documents related clipper variants targeting cryptocurrency addresses and a leaked stealer (Stealerium), highlights delivery vectors (phishing, malicious URLs, bundled software), and includes proof‑of‑concept demonstrations and forum postings observed by Cyble Research Labs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
