Rust Clipboard Hijacker Steals Crypto via Fake GitHub Stars
Key Takeaways A sophisticated malware campaign is actively stealing cryptocurrency by replacing wallet addresses copied to clipboards. The threat leverages a Rust-based clipboard hijacker distributed...
Key Takeaways
- A sophisticated malware campaign is actively stealing cryptocurrency by replacing wallet addresses copied to clipboards.
- The threat leverages a Rust-based clipboard hijacker distributed through fake “profit” tools like Solana sniper bots and gambling predictors.
- Attackers employ extensive social engineering, including fake GitHub stars, SourceForge downloads, and VirusTotal upvotes, to lend credibility to their malicious software.
- The malware establishes persistence on both Windows and macOS, making removal difficult without specific intervention.
A new and insidious malware operation is siphoning cryptocurrency from unsuspecting users by deploying a Rust-based clipboard hijacker. This campaign stands out due to its elaborate social engineering tactics, which include fabricating legitimacy through fake GitHub stars and other deceptive online reputation metrics.
Table Of Content
Instead of relying on conventional attack vectors, the perpetrator has meticulously constructed a convincing facade across various online platforms. This intricate web of deception makes dangerous software appear trustworthy, allowing it to bypass many traditional security defenses, as detailed in a recent report.
The core of this operation is a clipboard hijacking malware written in Rust, a programming language valued for its performance and low-level control. Once installed, the malware operates stealthily in the background, continuously monitoring the user’s clipboard for copied cryptocurrency wallet addresses. Upon detection, it surreptitiously replaces the legitimate address with one controlled by the attacker. This swap ensures that when a victim initiates a transfer, their funds are redirected to the attacker’s wallet, often with no recourse for recovery.
Analysts at Check Point Research have uncovered the full scope of this campaign, highlighting the attacker’s creation of an entire ecosystem designed to deliver and conceal the malware. The operation primarily targets cryptocurrency traders, online gamblers, and individuals seeking quick profits. Lures include deceptive tools such as Solana sniper bots, Aviator Predictors, and crash-game forecasters.
None of these advertised tools function as promised; their sole purpose is to act as conduits for delivering the clipboard hijacker. What truly sets this campaign apart is the sophisticated web of fake credibility. The attacker utilizes a WordPress phishing site as a central distribution point, directing victims to GitHub, SourceForge, and YouTube, all of which display artificially inflated engagement metrics from fake accounts. This, coupled with low detection rates on various security platforms, creates a compelling illusion of legitimacy that can even fool cautious users.
Rust Clipboard Hijacker
The threat actor manages at least six GitHub accounts, including “Decryptor-j,” “crash-predictor1,” and “roblox-script1.” These accounts employ “Ghost Networks” to artificially inflate repository stars and forks. For instance, one repository showed 146 stars and 62 forks, all likely generated by a coordinated network of fake accounts.

From GitHub alone, researchers documented over 5,000 downloads, with more than 1,250 attributed to the macOS “Aviator Predictor” tool.
SourceForge data reveals a similar pattern, with 44,485 total downloads, many of which appear suspicious. A significant portion of these downloads originated from Android devices, despite the malware only being available for Windows and macOS. This anomaly strongly suggests the use of an Android device farm to artificially boost download counts.

The deception extends to VirusTotal, where some malware samples received positive votes and “safe” community comments. Check Point Research noted that this manipulation of sentiment, combined with already low antivirus detection rates, can mislead both human users and automated reputation-based security systems. This tactic doesn’t make the files genuinely safer, but it successfully creates that impression, which is sufficient for the attackers’ goals.
How the Clipboard Hijacker Actually Works
For Windows users, the attack begins with downloading a ZIP archive and executing a file such as “SniperBot_Premium(Free).exe.” This is a .NET loader designed to silently launch a hidden executable named “silkebin.exe,” which is the actual Rust-based clipboard hijacker. The malware then establishes persistence by installing itself in a startup folder, ensuring it automatically launches with every system boot.

The hijacker continuously monitors clipboard changes, using regular expressions to identify cryptocurrency addresses for various digital assets, including Bitcoin, Ethereum, Litecoin, Tron, XRP, Monero, Cardano, and Dogecoin.
When a cryptocurrency address is detected, the malware instantly replaces it with one from a vast internal list of over 15,500 attacker-controlled wallets. These wallets are frequently rotated, with used addresses being replaced after each successful transaction to maximize obfuscation and evade tracking.
On macOS, victims are prompted to run “unlocker.command.” This script bypasses macOS security warnings and automatically launches the malicious application. The macOS variant installs a LaunchAgent for persistence and incorporates a self-healing watchdog loop. This loop constantly rewrites its own files, making the malware exceptionally difficult to remove without first terminating its active process.
Users are strongly advised to exercise extreme caution and verify the authenticity of any software promising automated trading profits or gambling shortcuts, particularly if sourced from unofficial channels. Always meticulously cross-reference every character of a cryptocurrency wallet address before confirming any transaction. Critically, never base trust in a file solely on its GitHub star count, download statistics, or community comments on platforms like VirusTotal.
What You Should Do
- Verify Wallet Addresses: Always double-check cryptocurrency wallet addresses character by character before initiating any transaction. Consider using the first few and last few characters for quick verification, but a full review is best.
- Be Skeptical of “Free Money” Tools: Avoid downloading software that promises guaranteed profits from crypto trading, gambling, or other high-yield schemes, especially from unofficial sources. These are common lures for malware.
- Download Software from Official Sources: Only download applications and tools from their official vendor websites or trusted app stores. Avoid third-party repositories, forums, or direct download links found in online discussions.
- Use Reputable Security Software: Ensure your operating system and antivirus/anti-malware solutions are up-to-date. While this malware aims to evade detection, layered security is crucial.
- Educate Yourself: Understand the risks associated with cryptocurrency transactions and common social engineering tactics. If something seems too good to be true, it almost certainly is.
Indicators of Compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| SHA-256 | 5518942d9d21794aaeff41a01b88606a96659fc329b481a2f0946d8163ab4d61 |
Clipboard Hijacking Malware |
| SHA-256 | 33c86ecfc324de3af97150bd009aba7925a6ba7a0842e127e94cf351013c0fe6 |
Clipboard Hijacking Malware |
| SHA-256 | 7a7ad4ae347a3f99f3773a113d9f70ecfa967100c96e8275bd1df833caee68d1 |
Clipboard Hijacking Malware |
| SHA-256 | bad8625087a7b9453c70933c0db32518ff5818e3d83f3a9e78d432a22b383edb |
Clipboard Hijacking Malware |
| SHA-256 | c1435847b0c437f91efb07a3a35e4468036322d7acf4ba9e6d363cec0b481241 |
Clipboard Hijacking Malware |
| SHA-256 | ef9a915c8e1d484e52b3287c94a58ecd22c07391a87f9c136eabd8397ed01ca2 |
Clipboard Hijacking Malware |
| SHA-256 | 5518942d9d21794aaeff41a01b88606a96659fc329b481a2f0946d8163ab4d61 |
Clipboard Hijacking Malware |
| SHA-256 | e02e60a23297692637b43ebcd7dbeb63af1e9680c551586a1ce935218e0034be |
Clipboard Hijacking Malware |
| SHA-256 | fb8294b12f904dff2ac79b51872be7bf09ab422cde223caaf4762eadf7e0760d |
Clipboard Hijacking Malware |
| SHA-256 | a91c09e0eea610dbe5879798f9cf12e3ce51e4e6f0893278bcdf3ebe22c4730b |
Clipboard Hijacking Malware |
| SHA-256 | 9c566db1ef9d08ee389d2b8cc1c50c65870096130c8bd2cf41ea14c4075e94c0 |
Clipboard Hijacking Malware |
| SHA-256 | f737e99177cc05037ff34cf6e245dd56377dc3db4e2bb46edcf039df650939d6 |
.NET Loader |
| SHA-256 | 7a9632bbecc31d02fdd0eab07e2424b3e1c9e9a3f91aac4ef6f708f2befbaa3d |
.NET Loader |
| SHA-256 | b71efdebd0ca3563e67edb7ad59358a6b8f013b219ad65033efcf48fd1c86619 |
macOS Clipboard Hijacking Malware |
| SHA-256 | 6f12c066a929c96104796c4ecca938754962009ebd9e4ba5329bb940bf331d0a |
macOS Loader |
| Crypto Wallet | bc1qr8vgrcvacyea68gk6w0kdzt2xcc93azzhalyjl9 |
Attacker BTC Bech32 wallet (macOS) |
| Crypto Wallet | 1JKeTeM7H3P1hj2DYB6vnXWeJ7XgKvXb7D |
Attacker BTC Legacy wallet (macOS) |
| Crypto Wallet | 3EBa4JbKY3HJx6KZopR1sV1upEvxm3dwR1 |
Attacker BTC P2SH wallet (macOS) |
| Crypto Wallet | 0x22f24a22b6f824E9ef76B05B186c4D0C2Df58d67 |
Attacker Ethereum/EVM wallet (macOS) |
| Crypto Wallet | 48SWwQ7QUSSPhHS9zWF9V9TKyK7FZVxDd9LghKbbkkYzB3AbhyKaCozMc26siguA2b6tce6tztCTXCWgyrypBLmW7HRxs6D |
Attacker Monero wallet (macOS) |
| Crypto Wallet | bnb1aj96a2f8655rl2hdrzghlagjpe2nm40tp7jq2v |
Attacker Binance Chain wallet (macOS) |
| Crypto Wallet | DDrusqzPjEovYyFrtDV8PVZVZDFFvpGAkc |
Attacker Dogecoin wallet (macOS) |
| Crypto Wallet | 7UQuwTTbZ9SoMY1E8D3DMyPjFCPCXjED2wcj8uhshyzW |
Attacker Solana wallet (macOS) |
| Crypto Wallet | TBFqTqF17fRvSXDh7U8k5mVFxjqkKrWUXm |
Attacker TRON wallet (macOS) |
| Crypto Wallet | rfzq3PnZAt6eFKcJ9TXHsAm2c8GuguHUc1 |
Attacker XRP wallet (macOS) |
| Telegram Handle | @JoseCmanXD |
Threat actor contact handle across phishing site, YouTube, and hacking forums |
| GitHub Account | Decryptor-j |
Threat actor GitHub account |
| GitHub Account | crash-predictor1 |
Threat actor GitHub account |
| GitHub Account | roblox-script1 |
Threat actor GitHub account |
| GitHub Account | hack-scripts |
Threat actor GitHub account |
| GitHub Account | stake-mines |
Threat actor GitHub account |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.