Clipper Malware disguised as AvD Crypto Stealer
ID: d4fa3dba-c233-5b92-ade6-d4c98485e3ef
STIX ID: report--d4fa3dba-c233-5b92-ade6-d4c98485e3ef
Feed Name: Cyble Blog
This report analyzes a .NET-based clipper malware disguised as an "AvD crypto stealer" that monitors the Windows clipboard, detects cryptocurrency addresses via regex, and replaces them with attacker-controlled addresses to divert funds. It details installation (self-extracting SFX), persistence (startup copy, mutex), classes and functions (clipboard monitoring, address config, regex patterns), targeted chains (Ethereum, BSC, Fantom, Polygon, Avalanche, Arbitrum, plus BTC/XMR references), IoCs (file hashes), MITRE ATT&CK mappings, and recommended mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
