Crypto clipboard-hijacker campaign weaponises VirusTotal community reputation to suppress detection
Check Point Research detailed a Rust-based clipboard-hijacker campaign against cryptocurrency users whose distinguishing feature is the systematic manipulation of security-tool reputation signals (Check Point Research, 2026-06-17). The operator runs a network of GitHub ghost accounts, SourceForge pages with inflated download counts, AI-narrated YouTube channels and Telegram channels advertising fake crypto "edge" tools (Solana/Pump.fun sniper bots, Aviator predictors), funnelling victims through a WordPress phishing site to download the Rust payloads for Windows and macOS. Critically, the actor submits fake benign community votes and comments on VirusTotal to lower the apparent threat score, so triage analysts relying on community reputation see the sample as pre-vetted. The payload watches the clipboard for wallet-address patterns and silently substitutes attacker addresses. The operational takeaway for SOC triage: VirusTotal community votes/comments are not a trust signal for this malware class — weight first-party engine verdicts and behaviour, and add clipboard-modification (T1115) hooks plus Rust binaries executing from user Downloads/Temp without code-signing to hunt hypotheses.
ATT&CK mapping
1 technique mapped from the cited reporting · MITRE ATT&CK v19.2
Collection TA0009
T1115Clipboard Data
Adversaries may collect data stored in the clipboard from users copying information within or between applications.
AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.