A new clipboard stealer (recently discovered) called Laplas Clipper uses cryptocurrency wallet addresses that resemble the address of the person intended to receive the money.

Laplas is a new type of malware that is more sophisticated than other types of information-stealing malware. The new clipper allows hackers to have better control over their operations and see which ones are most effective.
See also: Black Basta ransomware group linked to FIN7 group
The tool is provided under a subscription model, with the most expensive tier costing $549 for one year of access to the online dashboard that allows hackers to monitor and control their attacks.

In less than two weeks, the number of Laplas Clipper samples increased from under 20 per day to 55 by the end of last month, as security researchers at Cyble noted in a recent report.
Laplas is currently distributed via Smoke Loader and Raccoon Stealer 2.0, which proves that it has caught the attention of the cybercrime world.
See also: Dozens of PyPI packages found to be “dropping” info-stealing malware W4SP
The Laplace method
Common clipboard stealers, also known as clippers, take action when they spot a cryptocurrency wallet address that users typically copy for a payment. These activities are detected by monitoring the Windows clipboard.
When this happens, the clipper changes the address to one belonging to a cybercriminal in order to redirect the money to them.
Laplas developers devised a new system to fool experienced crypto users by using addresses that closely resembled those copied by the victim.

It's unclear how hackers obtain addresses that are similar to the original entry. When BleepingComputer tested it, it was able to generate a comparable address in just five seconds.
However, this additional work could raise suspicions among users.
One possible explanation is that the hackers created a large number of addresses in advance and Laplas selected those that corresponded to those the victim had used.
See also: Vodafone Italia reveals data breach – a reseller was hacked
Cyble notes that this process occurs on the attacker's server, so the exact mechanism remains unknown. Finding an address that is similar to the one the victim pasted into the clipboard is done using regular expressions.

Cyble told BleepingComputer that upon closer inspection, she discovered that Laplas retrieved a Bitcoin address that matched the first and last characters of the one she had pasted into the clipboard.
However, in the case of Ethereum, the address received from the attacker's server looked nothing like the original one he tried to forge.
Clipper generates wallet addresses for Bitcoin, Bitcoin Cash, Litecoin, Ethereum, Dogecoin, Monero, Algorand, Ravecoin, Ripple, Zcash, Dash, Ronin, Tron, Tezos, Solana, Cardano, Cosmos, Qtum and Steam Trade URLs.

In the author's promotional post on the dark web, it is stated that new addresses are created in less than a second and added to the web panel along with the rest of them.
The wallets created are stored in the database for three days, but operators can send the access keys to their Telegram to take control of the wallets later.
Users can also choose to receive real-time notifications about clipper actions on exposed hosts, such as the theft of a significant amount of money.

Stay safe
It is best to avoid downloading executable files from unknown websites and opening file attachments received via email.
Always validate the recipient address of the cryptocurrency transaction to avoid any problems.
By storing wallet seeds in encrypted form, it will be more difficult for cybercriminals to gain access to cryptocurrency funds if they are able to obtain the information.
Information source: bleepingcomputer.com
