Last seven days
- First activity
- Aug 1, 2026
- Last activity
- Aug 8, 2026
- Feed role
- C2 / Distribution
- Host form
- 34 IP / 20 hostnames
AnimateClipper is a cryptocurrency clipper malware family that monitors the Windows clipboard and replaces copied wallet addresses with attacker-controlled alternatives, enabling silent redirection of cryptocurrency transactions.
Profile source: Mallory opens in a new tabAnimateClipper
AnimateClipper is a cryptocurrency clipper malware family that monitors the Windows clipboard and replaces copied wallet addresses with attacker-controlled alternatives, enabling silent redirection of cryptocurrency transactions. It is associated with large-scale malware distribution campaigns that impersonate legitimate software download sites, including portals for developer, reverse-engineering, and freeware tools, and that use search-engine manipulation and gated traffic distribution infrastructure to selectively deliver payloads.
Observed delivery includes ClickFix-style lures in which victims are presented with a fake verification prompt and tricked into launching a remote script through native Windows utilities. Reported infection chains include script-based staging, PowerShell execution, RC4 decryption, use of a bundled Python environment, and in-memory shellcode execution before the final payload is loaded. The malware has been described as supporting more than 20 blockchain ecosystems.
AnimateClipperβs core function is crypto theft through clipboard substitution rather than credential harvesting. By silently hijacking copied wallet addresses, it can cause victims to send funds to attacker-controlled wallets without obvious signs of compromise. It has been observed alongside other payloads such as RemusStealer and SessionGate in campaigns that rely on fake software sites, SEO poisoning, and traffic filtering to evade researchers and deliver malware selectively. The malware targets Windows systems and is particularly relevant to users downloading software from impersonation sites and to cryptocurrency users whose transactions depend on clipboard-copied wallet addresses.
C2 tracking
Derp observations, rolling seven-day window
Samples
387a137898168fac861ad9b32ec2bb344ea745bc917b7a2d6f77f32887437667 46acea6234c6f736875da166cc4ab5846e8500068bee2c242b87a003cd6272fb 63f0720dea3e6f48af33d3917d4bec7124b542e64ad90a4d2aceb9e576e5b226 87a10c0338964875fba1a93f4c3b162cd384b242e9e6e6cfb7faa4ce4db2c7ba b40cb47ab1775a4be4ec9b997b58bedfeb2076079df0804dc80982c0309fa9a2 2fcad226b17131da4274e1b9f8f31359bdd325c9568665f08fd1f6c5d06a23ce 4e5cc8cb98584335400d00f0a0803c3e0202761f3fbe50bcab3858a80df255e1 c322fa3e02a79ecead674bc4a8e67b71d14632427f8dc9a380b0f588941bbf1a f270a80b90acb4302bb29b2f4c7436f6d7eedc4738ca63351f59f22bd59ce28d f5ebd8f8e5217df1c726beb523c00d49992d6d205589509cbe2c581b6aab29b6 MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.