Last seven days
- First activity
- Jul 27, 2026
- Last activity
- Jul 27, 2026
- Feed role
- C2
- Host form
- 5 IP / 0 hostnames
Efimer is a Trojan and cryptocurrency-focused stealer/ClipBanker identified by Kaspersky, with activity assessed from at least October 2024 through July 2025.
Profile source: Mallory opens in a new tabEfimer
Efimer is a Trojan and cryptocurrency-focused stealer/ClipBanker identified by Kaspersky, with activity assessed from at least October 2024 through July 2025. Kaspersky named it "Efimer" because that word appeared in a comment at the beginning of its decrypted script. Its core behavior is to steal cryptocurrency-related data and hijack transactions by replacing copied wallet addresses in the clipboard with attacker-controlled addresses. Reported targets include Bitcoin, Ethereum, and Monero wallets, with one torrent-delivered variant also spoofing Tron and Solana addresses. Efimer also steals mnemonic seed phrases from the clipboard, stores them temporarily in C:\Users\Public\controller\SEED, exfiltrates them, deletes the file, and captures screenshots after detecting mnemonic phrases.
Observed delivery vectors include compromised WordPress sites, malicious torrent lures, and phishing emails. In one June campaign, attackers impersonated lawyers alleging trademark infringement and delivered a ZIP archive named Demand_984175 (MD5: e337c507a4866169a7394d718bc19df9) containing a nested password-protected archive and an empty password file using Unicode character U+1D5E6 to hinder automated extraction. Execution of Requirement.wsf installed Efimer. Compromised WordPress sites were also used to host fake movie-download pages leading to password-protected archives and fake XMPEG packages; one observed lure was lovetahq[.]com/sinners-2025-torent-file/, and the package included xmpeg_player.exe as another Efimer installer.
On execution, the WSF installer checked for administrator privileges by attempting to write to C:\Windows\System32\wsf_admin_test.tmp. With elevated privileges it added C:\Users\Public\controller and several files or processes to Windows Defender exclusions and created persistence via a scheduled task using controller.xml. Without elevation it persisted through HKCU\Software\Microsoft\Windows\CurrentVersion\Run\controller and launched controller.js with WScript. Efimer also checked whether Task Manager was running and exited if detected.
Efimer downloaded a Tor proxy service from hardcoded URLs on compromised websites and saved it as C:\Users\Public\controller\ntdlg.exe. It communicated over Tor with at least one onion C2, cgky6bn6ux5wvlybtmm3z255igt52ljml2ngnc5qp3cnw5jlglamisad[.]onion, polled roughly every 30 minutes, and could execute arbitrary JavaScript returned in EVAL commands. It uploaded screenshots to recvf.php over Tor and reported both original and replacement wallet addresses after clipboard swaps. Victim identifiers were observed in formats including vs1a-XXXX and vt05-XXXX.
Kaspersky also linked auxiliary components and related scripts to the same operation. The script btdlg.js (MD5: 0f5404aa252f28c61b08390d52b7a054) brute-forced WordPress passwords using XML-RPC metaWeblog.newPost requests and /wp-json/wp/v2/users enumeration, sending successful credentials to C2 with the GOOD command. Another related script, liame.js, harvested email addresses from websites and likely supported spam or form-submission abuse. A related variant, assembly.js (MD5: 100620a913f0e0a538b115dbace78589), scanned browser extension and wallet application directories for cryptocurrency wallets, checked for virtualized environments, and communicated with a separate onion C2 at he5vnov645txpcv57el2theky2elesn24ebvgwfoewlpftksxp4fnxad[.]onion, supporting RPLY, EVAL, and KILL commands.
Separate reporting from Breakglass Intelligence assessed a NativeAOT .NET stealer delivered via ClickFix/FakeCaptcha and DLL sideloading as likely related to the ACRStealer/Efimer family. That stealer was described as capable of credential theft, cookie extraction, browser data harvesting, crypto wallet theft, and screenshot capture, and communicated over HTTPS/TLS 1.3. This linkage was assessed as likely rather than definitive.
Kaspersky reported 5,015 affected users from October 2024 through July 2025, with Brazil having the highest number of detections, followed by India, Spain, Russia, Italy, and Germany. Kaspersky detections for this threat include HEUR:Trojan-Dropper.Script.Efimer, HEUR:Trojan-Banker.Script.Efimer, HEUR:Trojan.Script.Efimer, and HEUR:Trojan-Spy.Script.Efimer.gen.
C2 tracking
Derp observations, rolling seven-day window
Samples
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.