From Stars to Upvotes: Fake Reputation Fueling a Crypto Clipboard Hijacker

    Date: 06/23/2026

    Severity: Medium

    Summary

    Threat actors are distributing a Rust-based cryptocurrency clipboard hijacker through a coordinated ecosystem of phishing websites, fake GitHub and SourceForge projects, AI-generated YouTube content, and manipulated reputation signals. The campaign uses fake popularity metrics, positive reviews, and benign VirusTotal comments to create a false sense of legitimacy and trick users seeking crypto trading and gambling tools. Once installed, the malware monitors clipboard activity and replaces cryptocurrency wallet addresses with attacker-controlled wallets to steal funds from victims. 

    Indicators of Compromise (IOC) List 

    Hash

    5518942d9d21794aaeff41a01b88606a96659fc329b481a2f0946d8163ab4d61

    33c86ecfc324de3af97150bd009aba7925a6ba7a0842e127e94cf351013c0fe6

    7a7ad4ae347a3f99f3773a113d9f70ecfa967100c96e8275bd1df833caee68d1

    bad8625087a7b9453c70933c0db32518ff5818e3d83f3a9e78d432a22b383edb

    c1435847b0c437f91efb07a3a35e4468036322d7acf4ba9e6d363cec0b481241

    ef9a915c8e1d484e52b3287c94a58ecd22c07391a87f9c136eabd8397ed01ca2

    5518942d9d21794aaeff41a01b88606a96659fc329b481a2f0946d8163ab4d61

    e02e60a23297692637b43ebcd7dbeb63af1e9680c551586a1ce935218e0034be

    fb8294b12f904dff2ac79b51872be7bf09ab422cde223caaf4762eadf7e0760d

    a91c09e0eea610dbe5879798f9cf12e3ce51e4e6f0893278bcdf3ebe22c4730b

    9c566db1ef9d08ee389d2b8cc1c50c65870096130c8bd2cf41ea14c4075e94c0

    f737e99177cc05037ff34cf6e245dd56377dc3db4e2bb46edcf039df650939d6

    7a9632bbecc31d02fdd0eab07e2424b3e1c9e9a3f91aac4ef6f708f2befbaa3d

    b71efdebd0ca3563e67edb7ad59358a6b8f013b219ad65033efcf48fd1c86619

    6f12c066a929c96104796c4ecca938754962009ebd9e4ba5329bb940bf331d0a

    Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection

    Detection Query 1 :

    sha256hash IN ("33c86ecfc324de3af97150bd009aba7925a6ba7a0842e127e94cf351013c0fe6","fb8294b12f904dff2ac79b51872be7bf09ab422cde223caaf4762eadf7e0760d","a91c09e0eea610dbe5879798f9cf12e3ce51e4e6f0893278bcdf3ebe22c4730b","c1435847b0c437f91efb07a3a35e4468036322d7acf4ba9e6d363cec0b481241","7a7ad4ae347a3f99f3773a113d9f70ecfa967100c96e8275bd1df833caee68d1","ef9a915c8e1d484e52b3287c94a58ecd22c07391a87f9c136eabd8397ed01ca2","9c566db1ef9d08ee389d2b8cc1c50c65870096130c8bd2cf41ea14c4075e94c0","b71efdebd0ca3563e67edb7ad59358a6b8f013b219ad65033efcf48fd1c86619","7a9632bbecc31d02fdd0eab07e2424b3e1c9e9a3f91aac4ef6f708f2befbaa3d","e02e60a23297692637b43ebcd7dbeb63af1e9680c551586a1ce935218e0034be","bad8625087a7b9453c70933c0db32518ff5818e3d83f3a9e78d432a22b383edb","5518942d9d21794aaeff41a01b88606a96659fc329b481a2f0946d8163ab4d61","5518942d9d21794aaeff41a01b88606a96659fc329b481a2f0946d8163ab4d61","f737e99177cc05037ff34cf6e245dd56377dc3db4e2bb46edcf039df650939d6","6f12c066a929c96104796c4ecca938754962009ebd9e4ba5329bb940bf331d0a")

    Reference:    

    https://research.checkpoint.com/2026/from-stars-to-upvotes-fake-reputation-fueling-a-crypto-clipboard-hijacker/        


    Tags

    MalwarePhishingRust MalwarecryptocurrencyClipboard hijackingGitHubAIGamblingStealer

    « Previous ArticleNext Article »

    Comments

    No records to display

    Looking for Something?
    Threat Research Categories:
    Tags