This sneaky hijack malware replaces your crypto addresses with lookalikes

An illustration of Bitcoin with a financial value graph
(Image credit: eToro)

A brand new clipper malware has been found taking the theft of cryptocurrency to a whole new level, researchers have claimed.

Clippers are a well-known security threat, as they are malware variants that monitor the clipboard of a Windows-powered endpoint, and when they see that a user copied a cryptocurrency wallet address to the clipboard, they’ll replace it with an address belonging to the attacker. That way, when the victim sends their funds, they’re actually sending them to a wallet belonging to the attackers.

But the attack is quite easy to spot, especially for more security-aware users (which crypto users generally are) - all it takes is to cross-reference a couple of characters between the copied address and the pasted one, to see if they match. Usually, users would check the last few characters. 

Generating countless addresses?

That’s exactly the safety measure the new Laplas Clipper is looking to eliminate, and it does so by generating addresses that are seemingly identical to the authentic ones. 

Exactly how Laplas does this is not yet clear, researchers from Cyble said, as the process takes place on the attacker's server, and crypto addresses are sometimes a string of more than 40 characters. 

One of the potential answers is that the malware operators generated countless addresses in advance, and the tool just uses the one most closely resembling the authentic one, at the moment.

When BleepingComputer put the clipper to the test, it came out with mixed results. While bitcoin addresses matched the first, and the last few characters, Ethereum addresses were not even close. In general, the clipper hunts for addresses for these cryptocurrencies: Bitcoin, Ethereum, Bitcoin Cash, Litecoin, Dogecoin, Monero, Ripple, ZCash, Dash, Ronin, Tron, and Steam Trade URL.

The tool comes in a subscription model, with pricing being $29 for one Sunday, $59 for a month, $159 for three months, $299 for half a year, and $549 for a full year.

Via: BleepingComputer

TOPICS

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Android phone malware
Screen reading malware found in iOS app stores for first time - and it might steal your cryptocurrency
Representational image depecting cybersecurity protection
Fake video conferencing apps are targeting Web3 workers to steal their data
A digital themed isometric showing a neon padlock in the foreground, and a technological diagram of a processor logic board in the background.
LastPass 2022 hack fallout continues with millions of dollars more reportedly stolen
A concept image of someone typing on a computer. A red flashing danger sign is above the keyboard and nymbers and symbols also in glowing red surround it.
Fake Reddit sites found pushing Lumma Stealer malware
A white padlock on a dark digital background.
Developers targeted by malicious Microsoft VSCode extensions
A digital representation of a lock
Security experts are being targeted with fake malware discoveries
Latest in Security
Webex by Cisco banner on a Chromebook
Cisco warns some Webex users of worrying security flaw, so patch now
Red padlock open on electric circuits network dark red background
AI-powered cyber threats are becoming the biggest worry for businesses everywhere
Woman using iMessage on iPhone
Apple to take legal action against British Government over backdoor request
Red padlock open on electric circuits network dark red background
Aviaton firms hit by devious new polyglot malware
A laptop with a red screen with a white skull on it with the message: "RANSOMWARE. All your files are encrypted."
Major ransomware attack sees Tata Technologies hit - 1.4TB dataset with over 730,000 files allegedly stolen
Image of laptop infected with malware
Ransomware criminals are now sending their demands...by snail mail?
Latest in News
A hand holding a phone showing the Android Find My Device network
Android's Find My Device can now let you track your friends – and I can't decide if that's cool or creepy
Insta360 X4 360 degree camera without lens protector
Leaked DJI Osmo 360 image suggests GoPro and Insta360 should be worried – here's why
A YouTube Premium promo on a laptop screen
A cheaper YouTube Premium Lite plan just rolled out in the US – but you’ll miss out on these 4 features
Viaim RecDot AI true wireless earbuds
These AI-powered earbuds can also act as a dictaphone with transcription when left in their case
The socket interface of the Intel Core Ultra processor
Intel unveils its most powerful AI PCs yet - new Intel Core Ultra Series 2 processors pack in vPro for lightweight laptops and high-performance workstations alike
An Nvidia GeForce RTX 5070
Nvidia confirms that an RTX 5070 Founders Edition is coming... just not on launch day