Last seven days
- First activity
- Jul 19, 2026
- Last activity
- Jul 20, 2026
- Feed role
- C2 / Distribution
- Host form
- 2 IP / 4 hostnames
AnimateClipper is a cryptocurrency clipper malware family delivered in a large-scale fake-software download campaign documented by Check Point Research.
Profile source: Mallory opens in a new tabAnimateClipper
AnimateClipper is a cryptocurrency clipper malware family delivered in a large-scale fake-software download campaign documented by Check Point Research. The campaign used more than 100 spoofed websites impersonating popular tools such as Ghidra, dnSpy, ILSpy, SpiderFoot, and CrystalDiskMark, with CloudFront-hosted JavaScript and a Traffic Distribution System to selectively route victims. One delivery path used a ClickFix lure: a fake Cloudflare verification page instructed users to execute a remote script via mshta.exe, including an observed URL to https://185.0xA1.0xFB[.]58/navy.7z. The infection chain involved obfuscated VBScript, PowerShell, RC4 decryption, a bundled Python environment, a hidden loader in a deceptive file named node_modules.asar, and in-memory shellcode execution via ntdll!LdrCallEnclave before loading the final PE payload. AnimateClipper silently monitors the clipboard and replaces copied cryptocurrency wallet addresses with attacker-controlled addresses embedded in the binary, enabling transaction hijacking across more than 20 blockchain ecosystems. Check Point reported that the malware could resolve command-and-control by querying a smart contract through the BNB Smart Chain Testnet JSON-RPC endpoint; at the time of analysis, the contract response resolved to kr.hugo-lapp[.]co. Researchers also observed attacker wallet activity associated with the sample dating back to 2025-07-12 on the BNB Smart Chain Testnet, indicating the operation had likely been active for an extended period. The malware is associated with the same broader campaign that also distributed RemusStealer and the SessionGate loader, with notable victim telemetry reported from countries including the U.K., Germany, France, Poland, Brazil, Russia, and Turkey.
C2 tracking
Derp observations, rolling seven-day window
Samples
824c913c874d3300c7deefd16ea653d323cfa6a5a7680f10beb00a8cbfa398a4 9165775115574e755cc95bd2aa1a0b3efe2b20c720fb056cfe90669bf8c1d6ec de2242d7b25c7129db2db9d37c4d3b10388769a9d69c02ed24df4d9375ae9bfd 721ee517288044c75fe5ad6019c8b115c7c5f45770f2f2c38dea9e9d93896fce 99cd8530772b5bb986883ebfd09410bfd5328581a3e993472826eda78d6e3405 MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.