ctipilot.ch
← Back to Daily brief 2026-06-18
NOTABLEresearch

Crypto clipboard-hijacker campaign weaponises VirusTotal community reputation to suppress detection

discovered 2026-06-18 05:10 UTCrun 2026-06-18-aa7ee8172 sourcesmulti-source

Check Point Research detailed a Rust-based clipboard-hijacker campaign against cryptocurrency users whose distinguishing feature is the systematic manipulation of security-tool reputation signals (Check Point Research, 2026-06-17). The operator runs a network of GitHub ghost accounts, SourceForge pages with inflated download counts, AI-narrated YouTube channels and Telegram channels advertising fake crypto "edge" tools (Solana/Pump.fun sniper bots, Aviator predictors), funnelling victims through a WordPress phishing site to download the Rust payloads for Windows and macOS. Critically, the actor submits fake benign community votes and comments on VirusTotal to lower the apparent threat score, so triage analysts relying on community reputation see the sample as pre-vetted. The payload watches the clipboard for wallet-address patterns and silently substitutes attacker addresses. The operational takeaway for SOC triage: VirusTotal community votes/comments are not a trust signal for this malware class — weight first-party engine verdicts and behaviour, and add clipboard-modification (T1115) hooks plus Rust binaries executing from user Downloads/Temp without code-signing to hunt hypotheses.

ATT&CK mapping

1 technique mapped from the cited reporting · MITRE ATT&CK v19.2

Collection TA0009
T1115Clipboard Data

Adversaries may collect data stored in the clipboard from users copying information within or between applications.

overlap matrix · ATT&CK page ↗

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.