Find notable cyber news and cases, enriched with sources, timelines, and signals.

Ghost Networks crypto-clipper promotion campaign

Campaign
First reported
Last updated
Happening score
H score 15
2 unique sources, 2 articles

Summary

Hide ▲

Unknown threat actor is running an active June 2026 campaign that fakes legitimacy to distribute a Rust-based clipboard hijacker. The operation uses bogus GitHub stars, inflated SourceForge downloads, VirusTotal planted “safe” votes, AI-narrated YouTube tutorials, and a WordPress phishing page to push booby-trapped crypto tools. The hidden payload targets Windows and macOS clipboard data, swapping copied wallet addresses for attacker-controlled ones from an embedded list of more than 15,500 addresses. The promotion model turns public reputation signals into a distribution layer for theft.

Related Happenings

OkoBot hardware-wallet phrase theft campaign

Campaign
H score37 First: 15.07.2026 18:30 Last: 15.07.2026 18:30 Sources 1

About this happening: An active OkoBot campaign is driving hundreds of victimizations across more than 25 countries, showing broad coordinated malware activity. The operation uses overlapping d...

Amadey and StealC MaaS ecosystem and affiliate model

Threat Actor Meta
H score73 First: 24.06.2026 18:59 Last: 24.06.2026 18:59 Sources 1

About this happening: The Amadey and StealC ecosystems now operate as malware-as-a-service (MaaS) offerings, widening access to loader and stealer capabilities for paying customers and affi...

Rust-based clipboard hijacker spreading via fake crypto tools

Malware Activity
H score13 First: 18.06.2026 18:00 Last: 18.06.2026 18:00 Sources 1

How related: New analysis from Check Point Research traced the operation to a Rust-based clipboard hijacker, a "clipper" that swaps copied crypto wallet addresses for the attacker's own, built for both Windows and macOS.

About this happening: A Rust-based clipboard hijacker is spreading through fake crypto tools and silently replacing copied wallet addresses, putting Windows and macOS users at risk of theft...

Windows cryptocurrency clipper campaign targeting users via USB LNK worms

Campaign
H score32 First: 18.06.2026 17:30 Last: 18.06.2026 17:30 Sources 1

About this happening: A Windows cryptocurrency clipper campaign is actively targeting users since February 2026, putting clipboard data, wallet addresses, and seed phrases at risk. The operatio...

Windows cryptocurrency clipper malware using USB LNK worming and Tor C2

Malware Activity
H score29 First: 18.06.2026 17:30 Last: 18.06.2026 17:30 Sources 1

About this happening: A Windows-based cryptocurrency clipper has been active since February 2026, using USB-delivered LNK worming to steal wallet data and reroute payments. The malware adds...

Timeline

  1. 17.06.2026 21:14 3 articles · 28d ago

    Ghost Networks campaign promotes a Rust-based crypto clipboard hijacker

    Campaign Scope Update

    Check Point Research says an unknown threat actor used paid or promoted posts on legitimate news websites, fake accounts, a dedicated WordPress phishing page, GitHub and SourceForge projects, a YouTube channel created in July 2020, and coordinated VirusTotal activity to build trust around a Rust-based crypto clipboard hijacker hidden in Solana and Pump.fun sniper bots and crash-game predictors. The malware targets cryptocurrency asset holders and online gamblers, monitors Windows and macOS clipboards for wallet addresses, and swaps matching content with attacker-controlled addresses.

    Show sources