Skip to content

AnimateClipper

AnimateClipper is a cryptocurrency clipper malware family that monitors the Windows clipboard and replaces copied wallet addresses with attacker-controlled alternatives, enabling silent redirection of cryptocurrency transactions.

Profile source: Mallory opens in a new tab

AnimateClipper

Family profile

AnimateClipper is a cryptocurrency clipper malware family that monitors the Windows clipboard and replaces copied wallet addresses with attacker-controlled alternatives, enabling silent redirection of cryptocurrency transactions. It is associated with large-scale malware distribution campaigns that impersonate legitimate software download sites, including portals for developer, reverse-engineering, and freeware tools, and that use search-engine manipulation and gated traffic distribution infrastructure to selectively deliver payloads.

Observed delivery includes ClickFix-style lures in which victims are presented with a fake verification prompt and tricked into launching a remote script through native Windows utilities. Reported infection chains include script-based staging, PowerShell execution, RC4 decryption, use of a bundled Python environment, and in-memory shellcode execution before the final payload is loaded. The malware has been described as supporting more than 20 blockchain ecosystems.

AnimateClipper’s core function is crypto theft through clipboard substitution rather than credential harvesting. By silently hijacking copied wallet addresses, it can cause victims to send funds to attacker-controlled wallets without obvious signs of compromise. It has been observed alongside other payloads such as RemusStealer and SessionGate in campaigns that rely on fake software sites, SEO poisoning, and traffic filtering to evade researchers and deliver malware selectively. The malware targets Windows systems and is particularly relevant to users downloading software from impersonation sites and to cryptocurrency users whose transactions depend on clipboard-copied wallet addresses.

Capabilities

  • Crypto Theft
  • Defense Evasion

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 1, 2026
Last activity
Aug 8, 2026
Feed role
C2 / Distribution
Host form
34 IP / 20 hostnames

Leading locations

  • US17
  • DE10
  • NL6
  • PL6
  • LU4
  • CN2
  • BR1
  • CA1
  • GB1
  • HK1
  • RU1
  • SG1

Leading providers

  • Cloudflare, Inc.14
  • Ghosty Networks LLC5
  • ZORNTECH WEB SOLUTIONS4
  • DEDIK SERVICES LIMITED3
  • HostPapa3
  • DigitalOcean, LLC2

Infrastructure traits

  • Hosting 51
  • Anycast 14
  • Proxy 3

Samples

Recent associated samples

MITRE ATT&CK

AnimateClipper in ATT&CK

23 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.