ClipXDaemon Malware, a Stealthy Cryptocurrency Clipboard Hijacker on Linux
ID: 06199a25-e30b-5962-af14-349da68e6521
STIX ID: report--06199a25-e30b-5962-af14-349da68e6521
Feed Name: The Cyber Express
ClipXDaemon is a Linux clipboard-hijacking malware targeting X11 desktop environments to replace copied cryptocurrency wallet addresses with attacker-controlled ones. The report details a three-stage infection using a bincrypter-generated encrypted loader, an AES-256-CBC in-memory dropper, and an on-disk ELF daemon persisted via ~/.profile, plus stealth techniques (daemonization, prctl name spoofing), encrypted configuration (ChaCha20), 200ms clipboard polling with regex wallet detection for multiple cryptocurrencies, and observed attacker wallet addresses; the binary contains no C2 communication.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
