Skip to content
Malware family

AnimateClipper

AnimateClipper is a cryptocurrency clipper malware family delivered in a large-scale fake-software download campaign documented by Check Point Research.

Profile source: Mallory opens in a new tab

AnimateClipper

Family profile

AnimateClipper is a cryptocurrency clipper malware family delivered in a large-scale fake-software download campaign documented by Check Point Research. The campaign used more than 100 spoofed websites impersonating popular tools such as Ghidra, dnSpy, ILSpy, SpiderFoot, and CrystalDiskMark, with CloudFront-hosted JavaScript and a Traffic Distribution System to selectively route victims. One delivery path used a ClickFix lure: a fake Cloudflare verification page instructed users to execute a remote script via mshta.exe, including an observed URL to https://185.0xA1.0xFB[.]58/navy.7z. The infection chain involved obfuscated VBScript, PowerShell, RC4 decryption, a bundled Python environment, a hidden loader in a deceptive file named node_modules.asar, and in-memory shellcode execution via ntdll!LdrCallEnclave before loading the final PE payload. AnimateClipper silently monitors the clipboard and replaces copied cryptocurrency wallet addresses with attacker-controlled addresses embedded in the binary, enabling transaction hijacking across more than 20 blockchain ecosystems. Check Point reported that the malware could resolve command-and-control by querying a smart contract through the BNB Smart Chain Testnet JSON-RPC endpoint; at the time of analysis, the contract response resolved to kr.hugo-lapp[.]co. Researchers also observed attacker wallet activity associated with the sample dating back to 2025-07-12 on the BNB Smart Chain Testnet, indicating the operation had likely been active for an extended period. The malware is associated with the same broader campaign that also distributed RemusStealer and the SessionGate loader, with notable victim telemetry reported from countries including the U.K., Germany, France, Poland, Brazil, Russia, and Turkey.

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Jul 19, 2026
Last activity
Jul 20, 2026
Feed role
C2 / Distribution
Host form
2 IP / 4 hostnames

Leading locations

  • DE2
  • US2
  • PL1
  • SG1

Leading providers

  • Cloudflare, Inc.2
  • Ghosty Networks LLC2
  • Akamai Connected Cloud1
  • ZORNTECH WEB SOLUTIONS1

Infrastructure traits

  • Hosting 6
  • Anycast 2

Samples

Recent associated samples

MITRE ATT&CK

AnimateClipper in ATT&CK

18 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.