AnimateClipper is a cryptocurrency clipper that monitors the clipboard and substitutes copied cryptocurrency wallet addresses with attacker-controlled addresses, redirecting victim transactions. It supports wallet-address replacement across more than 20 blockchain ecosystems. The malware has been distributed through ClickFix social-engineering lures, including fraudulent software-download and fake verification pages that induce victims to execute attacker-provided commands. AnimateClipper has appeared in the PasteSwitch malware-delivery operation, which used impersonated software sites, search-engine manipulation, traffic-distribution filtering, and malicious advertising. Observed execution chains use script-based staging, PowerShell, a bundled Python environment, and in-memory shellcode execution. AnimateClipper can use BNB Smart Chain smart contracts as mutable command-and-control dead drops, allowing operators to rotate command-and-control infrastructure. It targets Windows systems and has been characterized as a persistent clipboard-replacement payload in PasteSwitch activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
регистрация доменов - на T1583.001 (Domains). Атакующие инвестируют в подготовку инфраструктуры задолго до раздачи пейлоадов
During a 48-hour window, the attackers pushed 108 malicious advertisements across five lure groups as part of the campaign, tracked as PasteSwitch.
The official HBO Max Reddit account was reportedly compromised and used in a malvertising campaign... The compromised account published 108 advertisements... promoting fake downloads.
This kicks off a complex chain involving PowerShell, RC4 decryption, a Python environment, and a hidden loader inside a deceptive file (node_modules.asar).
Its beginning contains an HTA page with obfuscated VBScript, which mshta.exe executes.
This kicks off a complex chain involving PowerShell, RC4 decryption, a Python environment, and a hidden loader inside a deceptive file (node_modules.asar).
The delivery system had already turned up behind fake Claude, Codex, Alfred, Homebrew, GitHub, utility, and wallet applications.
The official HBO Max Reddit account was reportedly compromised and used in a malvertising campaign... The compromised account published 108 advertisements... promoting fake downloads.
This kicks off a complex chain involving PowerShell, RC4 decryption... requiring a one-time key from yourfastcrc.com to decrypt subsequent payloads.
Маршрутизация Multi-hop Proxy (T1090.003, C2) TDS-цепочка из 4+ промежуточных нод для обфускации
Their controllers can retrieve a current command-and-control domain from Binance Smart Chain contracts, letting actors rotate infrastructure.
AnimateClipper and ZigClipper... utilized BNB Smart Chain contracts to store rotating C2 domains.
These pages load a CloudFront-hosted JavaScript staging layer that converts a click on a 'download' button/link into a handoff to a Traffic Distribution System (TDS). The TDS enforces strict gating: first-visit state, mandatory click confirmation, anti-bot/anti-analysis logic, VPN/datacenter filtering, and frequency capping.
88 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Clipboard-hijacking malware that persists on victim systems and replaces cryptocurrency addresses copied to the clipboard with attacker-controlled addresses.
Cryptocurrency clipper that replaces cryptocurrency wallet addresses in the victim clipboard with attacker-controlled addresses. It shares a 21-wallet-address configuration with ZigClipper and uses BNB Smart Chain contracts for rotating C2 domains.
Cryptocurrency clipper that substitutes copied wallet addresses with attacker-controlled addresses and obtains C2 information through Binance Smart Chain smart contracts.
A persistent clipboard-replacement tool that swaps cryptocurrency wallet addresses during victim transactions. Its C2 infrastructure is hosted on the blockchain.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.