Cryptocurrency exchange Binance is warning of an “ongoing” global threat targeting cryptocurrency users via malware .

Clipper malware, also known as ClipBankers, is a type of malware that Microsoft describes as cryware. It has capabilities to monitor the victim's clipboard activity and steal sensitive data that the user copies, including replacing cryptocurrency with those controlled by the attacker.
Read more: APT41 hacking gang uses StealthVector malware
In this way, digital asset transfers initiated from a compromised system are directed to a hacker, instead of the correct destination address.
“During the cut and paste, a cryware monitors the contents of a user’s clipboard and uses search patterns to detect and recognize strings that resemble legitimate wallet addresses,” the tech giant noted in 2022. “If the target user pastes or uses CTRL + V in an application window, the cryware replaces the contents of the clipboard with the hacker’s address.”
Binance, in a statement issued on September 13, 2024, stated that it is monitoring an extensive malware threat aimed at intercepting data stored on the clipboard, with the aim of exchanging cryptocurrency wallet addresses.
See also: StealC malware: Abuse of browser kiosk mode to steal credentials
“The issue saw a notable increase in activity, particularly on August 27, 2024, which resulted in significant financial losses for affected users,” the exchange said. “The malware is often distributed via unofficial apps and add-ons, primarily in Android and web apps, however iOS users should also remain vigilant.”
There are indications that these malicious applications are installed unintentionally by users when searching for software in their native language or through unofficial channels, mainly due to the restrictions they face in their countries.
The company also announced that it is taking steps to block the hacker's addressesin order to prevent further fraudulent transactions. It has also notified affected users, advising them to check for signs of suspicious software or other unwanted activity.
In addition to urging users to avoid downloading software from unofficial sources, Binance recommends being cautious when installing apps and add-ons, ensuring their authenticity.

Blockchain analytics firm Chainalysis reported last month that overall illicit activity on the chain has fallen by nearly 20% since the start of the year. However, the inflow of stolen funds has nearly doubled, rising from $857 million to $1.58 billion.
Read more: Linux malware gang exploits Oracle Weblogic for cryptocurrency mining
“Hackers have largely stopped using large-scale Ponzi schemes and have shifted to more targeted campaigns, such as pig butchering scams, work-from-home scams, drainer scams, and address poisoning scams,” he said, adding that he has noticed “an increase in the use of Chinese-language marketplaces and money laundering networks.”
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: thehackernews
