logo

Clipper Malware disguised as AvD Crypto Stealer

ID: d4fa3dba-c233-5b92-ade6-d4c98485e3ef

STIX ID: report--d4fa3dba-c233-5b92-ade6-d4c98485e3ef

Feed Name: Cyble Blog

Threat Score
70/100

Date Published: 2025-05-20

Date Updated: 2026-07-16

...
...

This report analyzes a .NET-based clipper malware disguised as an "AvD crypto stealer" that monitors the Windows clipboard, detects cryptocurrency addresses via regex, and replaces them with attacker-controlled addresses to divert funds. It details installation (self-extracting SFX), persistence (startup copy, mutex), classes and functions (clipboard monitoring, address config, regex patterns), targeted chains (Ethereum, BSC, Fantom, Polygon, Avalanche, Arbitrum, plus BTC/XMR references), IoCs (file hashes), MITRE ATT&CK mappings, and recommended mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.