Skip to content

AnimateClipper

AnimateClipper is a cryptocurrency clipper malware family that monitors the Windows clipboard and replaces copied wallet addresses with attacker-controlled alternatives, enabling silent redirection of cryptocurrency transfers.

Profile source: Mallory opens in a new tab

AnimateClipper

Family profile

AnimateClipper is a cryptocurrency clipper malware family that monitors the Windows clipboard and replaces copied wallet addresses with attacker-controlled alternatives, enabling silent redirection of cryptocurrency transfers. It is designed to hijack transactions across more than 20 blockchain ecosystems.

AnimateClipper has been observed in large-scale malware distribution operations that impersonate legitimate open-source, freeware, and Windows application download sites. In these campaigns, victims are funneled through traffic distribution infrastructure that filters users by factors such as geography, browser characteristics, VPN usage, and likely researcher activity before serving payloads. Delivery has also been associated with ClickFix-style lures, including fake verification prompts that trick users into launching remote script execution through native Windows utilities.

Observed infection chains use multiple staged components and obfuscation, including script-based loaders, PowerShell, a bundled Python environment, and in-memory shellcode execution before the final payload is loaded. The malwareโ€™s core function is clipboard surveillance and substitution of cryptocurrency wallet addresses, allowing theft of funds without obvious signs to the victim at the time of transfer. AnimateClipper has been linked to campaigns that also distributed Remus Stealer and the SessionGate framework, indicating use within broader malware delivery ecosystems rather than as a standalone operation.

The malware targets Windows systems and is primarily relevant to users who download software from spoofed project sites, especially security tools, developer tools, and popular freeware applications. Its operational objective is crypto theft rather than credential collection or ransomware-style disruption.

Capabilities

  • Crypto Theft
  • Defense Evasion

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 27, 2026
Last activity
Sep 3, 2026
Feed role
C2 / Distribution
Host form
41 IP / 10 hostnames

Leading locations

  • DE12
  • US9
  • NL8
  • HK5
  • CN3
  • LU2
  • MD2
  • PL2
  • RU2
  • CA1
  • SG1
  • SI1

Leading providers

  • Cloudflare, Inc.5
  • FEMO IT SOLUTIONS LIMITED5
  • CTG Server Limited4
  • Omegatech LTD4
  • DEDIK SERVICES LIMITED3
  • Ghosty Networks LLC3

Infrastructure traits

  • Hosting 48
  • Anycast 5

Samples

Recent associated samples

MITRE ATT&CK

AnimateClipper in ATT&CK

23 distinct techniques

Reporting

Research mentioning AnimateClipper

Aug 25
Security Affairs

Fake Minecraft Sites Are Still Spreading WeedHack After C2 Takedown

Malicious websites impersonating Minecraft clients, mods, and related tools are continuing to distribute the WeedHack malware family despite prior command-and-control disruption. McAfee Labs identified at least 10 active sites and multiple file-hosting accounts tied to the campaign, while McAfee WebAdvisor blocked more than 6,300 attempts to reach them in the past month. The lures are amplified through SEO poisoning, YouTube links, Discord, GitHub repositories, and trusted Minecraft community platforms, with attackers using convincing lookalike pages to trick gamers into downloading malicious files. The infection chain delivers Java JAR payloads that collect system information, add Microsoft Defender exclusions, and steal credentials, browser data, cookies, and cryptocurrency wallets from infected hosts. Earlier reporting linked the Malware-as-a-Service operation to at least 116,464 infected systems and 2,000 to 3,000 new victims per day, while researchers said the operators used EtherHiding to retrieve active server addresses from the Ethereum blockchain and keep the campaign resilient after takedowns. One spoofed site was reportedly built with the AI website builder Lovable, underscoring how easily attackers can create realistic malware-delivery infrastructure.

Aug 25
Cyber Security News

Top Google Results for Minecraft Client Led Gamers to Malware, McAfee Finds

Aug 24
The Hacker News

Weedhack Malware Spreads via Fake Minecraft Clients and SEO Poisoning

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.