Last seven days
- First activity
- Aug 27, 2026
- Last activity
- Sep 3, 2026
- Feed role
- C2 / Distribution
- Host form
- 41 IP / 10 hostnames
AnimateClipper is a cryptocurrency clipper malware family that monitors the Windows clipboard and replaces copied wallet addresses with attacker-controlled alternatives, enabling silent redirection of cryptocurrency transfers.
Profile source: Mallory opens in a new tabAnimateClipper
AnimateClipper is a cryptocurrency clipper malware family that monitors the Windows clipboard and replaces copied wallet addresses with attacker-controlled alternatives, enabling silent redirection of cryptocurrency transfers. It is designed to hijack transactions across more than 20 blockchain ecosystems.
AnimateClipper has been observed in large-scale malware distribution operations that impersonate legitimate open-source, freeware, and Windows application download sites. In these campaigns, victims are funneled through traffic distribution infrastructure that filters users by factors such as geography, browser characteristics, VPN usage, and likely researcher activity before serving payloads. Delivery has also been associated with ClickFix-style lures, including fake verification prompts that trick users into launching remote script execution through native Windows utilities.
Observed infection chains use multiple staged components and obfuscation, including script-based loaders, PowerShell, a bundled Python environment, and in-memory shellcode execution before the final payload is loaded. The malwareโs core function is clipboard surveillance and substitution of cryptocurrency wallet addresses, allowing theft of funds without obvious signs to the victim at the time of transfer. AnimateClipper has been linked to campaigns that also distributed Remus Stealer and the SessionGate framework, indicating use within broader malware delivery ecosystems rather than as a standalone operation.
The malware targets Windows systems and is primarily relevant to users who download software from spoofed project sites, especially security tools, developer tools, and popular freeware applications. Its operational objective is crypto theft rather than credential collection or ransomware-style disruption.
C2 tracking
Derp observations, rolling seven-day window
Samples
1b723594e574c00aac2c946ff738a0454f7c24f6ebc84ae45a6af9628b08cb96 40b643468356c0fd751893647ad0dc9e2a0019427e4f5f0e2f6e559efcecb977 508e710d673802a532798e7dffa3aefcfb36eff0acef1620b8614917ac62e53e 8d793a16bf2e7153df21e2ede4b0baf6e080596073b27ecbeac6613b6a68b8d8 d780677e97da00b2b90849741720c1a02e758356630b63242a18074775c69e1c 2373dac86dbe2f62f37a614c7b66646aaab87343e0f3dc77e90cde201e863082 6f73f5d8d8e7843414f4af4d1325841cf07dd769e9661462df3368083819a975 a3ba0f671df55e1515a13ab81946ac13deb8241fa2f4d9f2a7a6ab2cca26053e ad4ec9f24f9bb9a14da8c61b64959fd9d01819f4873703ddcf84fa131061125d ecdc7cb90d662c515a408c13a42c01461a493280515ddbe2b2337cb1ad0cc68e MITRE ATT&CK
Reporting
Malicious websites impersonating Minecraft clients, mods, and related tools are continuing to distribute the WeedHack malware family despite prior command-and-control disruption. McAfee Labs identified at least 10 active sites and multiple file-hosting accounts tied to the campaign, while McAfee WebAdvisor blocked more than 6,300 attempts to reach them in the past month. The lures are amplified through SEO poisoning, YouTube links, Discord, GitHub repositories, and trusted Minecraft community platforms, with attackers using convincing lookalike pages to trick gamers into downloading malicious files. The infection chain delivers Java JAR payloads that collect system information, add Microsoft Defender exclusions, and steal credentials, browser data, cookies, and cryptocurrency wallets from infected hosts. Earlier reporting linked the Malware-as-a-Service operation to at least 116,464 infected systems and 2,000 to 3,000 new victims per day, while researchers said the operators used EtherHiding to retrieve active server addresses from the Ethereum blockchain and keep the campaign resilient after takedowns. One spoofed site was reportedly built with the AI website builder Lovable, underscoring how easily attackers can create realistic malware-delivery infrastructure.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.