Close Menu
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
What's Hot

Kalshi faces state courts over illegal gambling claims

April 21, 2026

North Korean Blamed for $290m KelpDAO Crypto Heist

April 21, 2026

Is Tether’s $1B Ethereum mint early signal for stronger Q2 activity?

April 21, 2026
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook X (Twitter) Instagram
CryptoPulseDaily.com
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
CryptoPulseDaily.com
Home»Security and Privacy»Clipboard-Injector Attacks Target Cryptocurrency Users
Clipboard-Injector Attacks Target Cryptocurrency Users
Security and Privacy

Clipboard-Injector Attacks Target Cryptocurrency Users

May 24, 2023No Comments3 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

A malware campaign targeting cryptocurrency wallets has been recently discovered by security researchers at Kaspersky.

Discussing the findings in an advisory published today, the company said the attacks were first observed in September 2022 and relied on malware replacing part of the clipboard contents with cryptocurrency wallet addresses.

“Despite the attack being fundamentally simple, it harbors more danger than [it] would seem. And not only because it creates irreversible money transfers, but because it is so passive and hard to detect for a normal user,” reads the advisory.

Kaspersky added that this is particularly true when considering that while worms and viruses may not necessarily connect to the attacker’s control servers, they often generate visible network activity or increase CPU or RAM usage.

“So does encrypting ransomware. Clipboard injectors, on the contrary, can be silent for years, show no network activity or any other signs of presence until the disastrous day when they replace a crypto wallet address,” the company explained.

Read more on clipboard malware here: Researchers Release MortalKombat Ransomware Decryptor

Kaspersky added that the malware campaign relying on this technique was observed abusing Tor Browser installers.

“We relate this to the ban of Tor Project’s website in Russia at the end of 2021, which was reported by the Tor Project itself […] Malware authors heard the call and responded by creating trojanized Tor Browser bundles and distributing them among Russian-speaking users.”

As for the payload observed during the malicious campaign, Kaspersky explained it was a passive and communication-less clipboard-injector malware.

“The malware integrates into the chain of Windows clipboard viewers and receives a notification every time the clipboard data is changed,” reads the advisory. “If the clipboard contains text, it scans the contents with a set of embedded regular expressions. Should it find a match, it is replaced with one randomly chosen address from a hardcoded list.”

See also  German Police Take Down Kingdom Market Dark Web Marketplace

The clipboard-injector mainly targeted systems in Russia and Eastern Europe, but also in the US, Germany and China, among others.

To mitigate the impact of this threat, Kaspersky advised system defenders to download software from only reliable and trusted sources.

“A mistake likely made by all victims of this malware was to download and run Tor Browser from a third-party resource,” the company explained. “The installers coming from the official Tor Project were digitally signed and didn’t contain any signs of such malware.”

Malicious Tor Browser installers were also spread last year via an explanatory video about the Darknet on YouTube.

Source link

attacks ClipboardInjector Cryptocurrency Target users
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

North Korean Blamed for $290m KelpDAO Crypto Heist

April 21, 2026

Chainalysis Flags Critical Blind Spot in DeFi Security as $292M Exploit Bypasses Burn Verification

April 21, 2026

Ripple’s Schwartz Flags DeFi Bridge Trade-Offs After KelpDAO Incident

April 20, 2026

Layerzero Claims Zero Contagion After $290M Exploit as Disputed Narratives Deepen Scrutiny

April 20, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Coinbase in Talks to Acquire Crypto Options Exchange Deribit: Bloomberg

March 22, 2025

Hut 8 Secures $330M Credit From Two Prime, Coinbase to Back 1.5 GW US Expansion

August 28, 2025

US Treasury Sanctions Virtual Currency Mixer For Connections With Lazarus Group

June 16, 2023

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

Our mission is to develop a community of people who try to make financially sound decisions. The website strives to educate individuals in making wise choices about Crypto, ICOs, Web3, Blockchain and more.

We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

Kalshi faces state courts over illegal gambling claims

April 21, 2026

North Korean Blamed for $290m KelpDAO Crypto Heist

April 21, 2026

Is Tether’s $1B Ethereum mint early signal for stronger Q2 activity?

April 21, 2026
Get Informed

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2026 Crypto Pulse Daily - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.

Cleantalk Pixel
  • bitcoinBitcoin(BTC)$76,526.001.97%
  • ethereumEthereum(ETH)$2,326.570.97%
  • tetherTether(USDT)$1.000.00%
  • rippleXRP(XRP)$1.441.87%
  • binancecoinBNB(BNB)$636.581.71%
  • usd-coinUSDC(USDC)$1.000.00%
  • solanaSolana(SOL)$85.831.03%
  • tronTRON(TRX)$0.328761-0.23%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.031.33%
  • dogecoinDogecoin(DOGE)$0.0953940.96%