Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Mindgard Raises $30M to Secure AI Systems Against Emerging Threats
August 12, 2026
City-Forum Hackers Exploit Salesforce, ServiceNow Critical Vulnerabilities
August 12, 2026
Palo Alto Networks Patches 11 Vulnerabilities in PAN-OS, GlobalProtect, Prisma Access
August 12, 2026
Home/Threats/Rust Clipboard Hijacker Steals Crypto via Fake GitHub Stars
Threats

Rust Clipboard Hijacker Steals Crypto via Fake GitHub Stars

Key Takeaways A sophisticated malware campaign is actively stealing cryptocurrency by replacing wallet addresses copied to clipboards. The threat leverages a Rust-based clipboard hijacker distributed...

Emy Elsamnoudy
Emy Elsamnoudy
June 18, 2026 6 Min Read
51 0

Key Takeaways

  • A sophisticated malware campaign is actively stealing cryptocurrency by replacing wallet addresses copied to clipboards.
  • The threat leverages a Rust-based clipboard hijacker distributed through fake “profit” tools like Solana sniper bots and gambling predictors.
  • Attackers employ extensive social engineering, including fake GitHub stars, SourceForge downloads, and VirusTotal upvotes, to lend credibility to their malicious software.
  • The malware establishes persistence on both Windows and macOS, making removal difficult without specific intervention.

A new and insidious malware operation is siphoning cryptocurrency from unsuspecting users by deploying a Rust-based clipboard hijacker. This campaign stands out due to its elaborate social engineering tactics, which include fabricating legitimacy through fake GitHub stars and other deceptive online reputation metrics.

Table Of Content

  • Key Takeaways
  • Rust Clipboard Hijacker
  • How the Clipboard Hijacker Actually Works
  • What You Should Do

Instead of relying on conventional attack vectors, the perpetrator has meticulously constructed a convincing facade across various online platforms. This intricate web of deception makes dangerous software appear trustworthy, allowing it to bypass many traditional security defenses, as detailed in a recent report.

The core of this operation is a clipboard hijacking malware written in Rust, a programming language valued for its performance and low-level control. Once installed, the malware operates stealthily in the background, continuously monitoring the user’s clipboard for copied cryptocurrency wallet addresses. Upon detection, it surreptitiously replaces the legitimate address with one controlled by the attacker. This swap ensures that when a victim initiates a transfer, their funds are redirected to the attacker’s wallet, often with no recourse for recovery.

Analysts at Check Point Research have uncovered the full scope of this campaign, highlighting the attacker’s creation of an entire ecosystem designed to deliver and conceal the malware. The operation primarily targets cryptocurrency traders, online gamblers, and individuals seeking quick profits. Lures include deceptive tools such as Solana sniper bots, Aviator Predictors, and crash-game forecasters.

None of these advertised tools function as promised; their sole purpose is to act as conduits for delivering the clipboard hijacker. What truly sets this campaign apart is the sophisticated web of fake credibility. The attacker utilizes a WordPress phishing site as a central distribution point, directing victims to GitHub, SourceForge, and YouTube, all of which display artificially inflated engagement metrics from fake accounts. This, coupled with low detection rates on various security platforms, creates a compelling illusion of legitimacy that can even fool cautious users.

Rust Clipboard Hijacker

The threat actor manages at least six GitHub accounts, including “Decryptor-j,” “crash-predictor1,” and “roblox-script1.” These accounts employ “Ghost Networks” to artificially inflate repository stars and forks. For instance, one repository showed 146 stars and 62 forks, all likely generated by a coordinated network of fake accounts.

Repository with 146 stars and 62 forks (Source - Check Point)
Repository with 146 stars and 62 forks (Source – Check Point)

From GitHub alone, researchers documented over 5,000 downloads, with more than 1,250 attributed to the macOS “Aviator Predictor” tool.

SourceForge data reveals a similar pattern, with 44,485 total downloads, many of which appear suspicious. A significant portion of these downloads originated from Android devices, despite the malware only being available for Windows and macOS. This anomaly strongly suggests the use of an Android device farm to artificially boost download counts.

SourceForge download statistics (Source - Check Point)
SourceForge download statistics (Source – Check Point)

The deception extends to VirusTotal, where some malware samples received positive votes and “safe” community comments. Check Point Research noted that this manipulation of sentiment, combined with already low antivirus detection rates, can mislead both human users and automated reputation-based security systems. This tactic doesn’t make the files genuinely safer, but it successfully creates that impression, which is sufficient for the attackers’ goals.

How the Clipboard Hijacker Actually Works

For Windows users, the attack begins with downloading a ZIP archive and executing a file such as “SniperBot_Premium(Free).exe.” This is a .NET loader designed to silently launch a hidden executable named “silkebin.exe,” which is the actual Rust-based clipboard hijacker. The malware then establishes persistence by installing itself in a startup folder, ensuring it automatically launches with every system boot.

Execution of Rust Clipboard Hijacker (Source - Check Point)
Execution of Rust Clipboard Hijacker (Source – Check Point)

The hijacker continuously monitors clipboard changes, using regular expressions to identify cryptocurrency addresses for various digital assets, including Bitcoin, Ethereum, Litecoin, Tron, XRP, Monero, Cardano, and Dogecoin.

When a cryptocurrency address is detected, the malware instantly replaces it with one from a vast internal list of over 15,500 attacker-controlled wallets. These wallets are frequently rotated, with used addresses being replaced after each successful transaction to maximize obfuscation and evade tracking.

On macOS, victims are prompted to run “unlocker.command.” This script bypasses macOS security warnings and automatically launches the malicious application. The macOS variant installs a LaunchAgent for persistence and incorporates a self-healing watchdog loop. This loop constantly rewrites its own files, making the malware exceptionally difficult to remove without first terminating its active process.

Users are strongly advised to exercise extreme caution and verify the authenticity of any software promising automated trading profits or gambling shortcuts, particularly if sourced from unofficial channels. Always meticulously cross-reference every character of a cryptocurrency wallet address before confirming any transaction. Critically, never base trust in a file solely on its GitHub star count, download statistics, or community comments on platforms like VirusTotal.

What You Should Do

  • Verify Wallet Addresses: Always double-check cryptocurrency wallet addresses character by character before initiating any transaction. Consider using the first few and last few characters for quick verification, but a full review is best.
  • Be Skeptical of “Free Money” Tools: Avoid downloading software that promises guaranteed profits from crypto trading, gambling, or other high-yield schemes, especially from unofficial sources. These are common lures for malware.
  • Download Software from Official Sources: Only download applications and tools from their official vendor websites or trusted app stores. Avoid third-party repositories, forums, or direct download links found in online discussions.
  • Use Reputable Security Software: Ensure your operating system and antivirus/anti-malware solutions are up-to-date. While this malware aims to evade detection, layered security is crucial.
  • Educate Yourself: Understand the risks associated with cryptocurrency transactions and common social engineering tactics. If something seems too good to be true, it almost certainly is.

Indicators of Compromise (IoCs):-

Type Indicator Description
SHA-256 5518942d9d21794aaeff41a01b88606a96659fc329b481a2f0946d8163ab4d61 Clipboard Hijacking Malware
SHA-256 33c86ecfc324de3af97150bd009aba7925a6ba7a0842e127e94cf351013c0fe6 Clipboard Hijacking Malware
SHA-256 7a7ad4ae347a3f99f3773a113d9f70ecfa967100c96e8275bd1df833caee68d1 Clipboard Hijacking Malware
SHA-256 bad8625087a7b9453c70933c0db32518ff5818e3d83f3a9e78d432a22b383edb Clipboard Hijacking Malware
SHA-256 c1435847b0c437f91efb07a3a35e4468036322d7acf4ba9e6d363cec0b481241 Clipboard Hijacking Malware
SHA-256 ef9a915c8e1d484e52b3287c94a58ecd22c07391a87f9c136eabd8397ed01ca2 Clipboard Hijacking Malware
SHA-256 5518942d9d21794aaeff41a01b88606a96659fc329b481a2f0946d8163ab4d61 Clipboard Hijacking Malware
SHA-256 e02e60a23297692637b43ebcd7dbeb63af1e9680c551586a1ce935218e0034be Clipboard Hijacking Malware
SHA-256 fb8294b12f904dff2ac79b51872be7bf09ab422cde223caaf4762eadf7e0760d Clipboard Hijacking Malware
SHA-256 a91c09e0eea610dbe5879798f9cf12e3ce51e4e6f0893278bcdf3ebe22c4730b Clipboard Hijacking Malware
SHA-256 9c566db1ef9d08ee389d2b8cc1c50c65870096130c8bd2cf41ea14c4075e94c0 Clipboard Hijacking Malware
SHA-256 f737e99177cc05037ff34cf6e245dd56377dc3db4e2bb46edcf039df650939d6 .NET Loader
SHA-256 7a9632bbecc31d02fdd0eab07e2424b3e1c9e9a3f91aac4ef6f708f2befbaa3d .NET Loader
SHA-256 b71efdebd0ca3563e67edb7ad59358a6b8f013b219ad65033efcf48fd1c86619 macOS Clipboard Hijacking Malware
SHA-256 6f12c066a929c96104796c4ecca938754962009ebd9e4ba5329bb940bf331d0a macOS Loader
Crypto Wallet bc1qr8vgrcvacyea68gk6w0kdzt2xcc93azzhalyjl9 Attacker BTC Bech32 wallet (macOS)
Crypto Wallet 1JKeTeM7H3P1hj2DYB6vnXWeJ7XgKvXb7D Attacker BTC Legacy wallet (macOS)
Crypto Wallet 3EBa4JbKY3HJx6KZopR1sV1upEvxm3dwR1 Attacker BTC P2SH wallet (macOS)
Crypto Wallet 0x22f24a22b6f824E9ef76B05B186c4D0C2Df58d67 Attacker Ethereum/EVM wallet (macOS)
Crypto Wallet 48SWwQ7QUSSPhHS9zWF9V9TKyK7FZVxDd9LghKbbkkYzB3AbhyKaCozMc26siguA2b6tce6tztCTXCWgyrypBLmW7HRxs6D Attacker Monero wallet (macOS)
Crypto Wallet bnb1aj96a2f8655rl2hdrzghlagjpe2nm40tp7jq2v Attacker Binance Chain wallet (macOS)
Crypto Wallet DDrusqzPjEovYyFrtDV8PVZVZDFFvpGAkc Attacker Dogecoin wallet (macOS)
Crypto Wallet 7UQuwTTbZ9SoMY1E8D3DMyPjFCPCXjED2wcj8uhshyzW Attacker Solana wallet (macOS)
Crypto Wallet TBFqTqF17fRvSXDh7U8k5mVFxjqkKrWUXm Attacker TRON wallet (macOS)
Crypto Wallet rfzq3PnZAt6eFKcJ9TXHsAm2c8GuguHUc1 Attacker XRP wallet (macOS)
Telegram Handle @JoseCmanXD Threat actor contact handle across phishing site, YouTube, and hacking forums
GitHub Account Decryptor-j Threat actor GitHub account
GitHub Account crash-predictor1 Threat actor GitHub account
GitHub Account roblox-script1 Threat actor GitHub account
GitHub Account hack-scripts Threat actor GitHub account
GitHub Account stake-mines Threat actor GitHub account

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackExploitMalwarephishingSecurityThreat

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

Xctdoor Backdoor Delivered via PowerShell, VBScript, and BAT Files

Next Post

Critical Apache HTTP/2 DoS Vulnerability Gets Public Exploit

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Google Chrome 115 Patches Five High-Severity Use-After-Free Flaws
August 12, 2026
Eclipse Ransomware Launches RaaS, Targets Windows, Linux, ESXi
August 12, 2026
WhatsApp launches new scam alert feature to combat social engineering
August 12, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us