Ghost Networks crypto-clipper promotion campaign
Campaign
Summary
Hide ▲
Show ▼
Unknown threat actor is running an active June 2026 campaign that fakes legitimacy to distribute a Rust-based clipboard hijacker. The operation uses bogus GitHub stars, inflated SourceForge downloads, VirusTotal planted “safe” votes, AI-narrated YouTube tutorials, and a WordPress phishing page to push booby-trapped crypto tools. The hidden payload targets Windows and macOS clipboard data, swapping copied wallet addresses for attacker-controlled ones from an embedded list of more than 15,500 addresses. The promotion model turns public reputation signals into a distribution layer for theft.
Related Happenings
OkoBot hardware-wallet phrase theft campaign
Campaign
H score37
First: 15.07.2026 18:30
Last: 15.07.2026 18:30
Sources 1
About this happening:
An active OkoBot campaign is driving hundreds of victimizations across more than 25 countries, showing broad coordinated malware activity. The operation uses overlapping d...
OkoBot hardware-wallet phrase theft campaign
CampaignAbout this happening: An active OkoBot campaign is driving hundreds of victimizations across more than 25 countries, showing broad coordinated malware activity. The operation uses overlapping d...
Amadey and StealC MaaS ecosystem and affiliate model
Threat Actor Meta
H score73
First: 24.06.2026 18:59
Last: 24.06.2026 18:59
Sources 1
About this happening:
The Amadey and StealC ecosystems now operate as malware-as-a-service (MaaS) offerings, widening access to loader and stealer capabilities for paying customers and affi...
Amadey and StealC MaaS ecosystem and affiliate model
Threat Actor MetaAbout this happening: The Amadey and StealC ecosystems now operate as malware-as-a-service (MaaS) offerings, widening access to loader and stealer capabilities for paying customers and affi...
Rust-based clipboard hijacker spreading via fake crypto tools
Malware Activity
H score13
First: 18.06.2026 18:00
Last: 18.06.2026 18:00
Sources 1
How related:
New analysis from Check Point Research traced the operation to a Rust-based clipboard hijacker, a "clipper" that swaps copied crypto wallet addresses for the attacker's own, built for both Windows and macOS.
About this happening:
A Rust-based clipboard hijacker is spreading through fake crypto tools and silently replacing copied wallet addresses, putting Windows and macOS users at risk of theft...
Rust-based clipboard hijacker spreading via fake crypto tools
Malware ActivityHow related: New analysis from Check Point Research traced the operation to a Rust-based clipboard hijacker, a "clipper" that swaps copied crypto wallet addresses for the attacker's own, built for both Windows and macOS.
About this happening: A Rust-based clipboard hijacker is spreading through fake crypto tools and silently replacing copied wallet addresses, putting Windows and macOS users at risk of theft...
Windows cryptocurrency clipper campaign targeting users via USB LNK worms
Campaign
H score32
First: 18.06.2026 17:30
Last: 18.06.2026 17:30
Sources 1
About this happening:
A Windows cryptocurrency clipper campaign is actively targeting users since February 2026, putting clipboard data, wallet addresses, and seed phrases at risk. The operatio...
Windows cryptocurrency clipper campaign targeting users via USB LNK worms
CampaignAbout this happening: A Windows cryptocurrency clipper campaign is actively targeting users since February 2026, putting clipboard data, wallet addresses, and seed phrases at risk. The operatio...
Windows cryptocurrency clipper malware using USB LNK worming and Tor C2
Malware Activity
H score29
First: 18.06.2026 17:30
Last: 18.06.2026 17:30
Sources 1
About this happening:
A Windows-based cryptocurrency clipper has been active since February 2026, using USB-delivered LNK worming to steal wallet data and reroute payments. The malware adds...
Windows cryptocurrency clipper malware using USB LNK worming and Tor C2
Malware ActivityAbout this happening: A Windows-based cryptocurrency clipper has been active since February 2026, using USB-delivered LNK worming to steal wallet data and reroute payments. The malware adds...
Timeline
-
17.06.2026 21:14 3 articles · 28d ago
Ghost Networks campaign promotes a Rust-based crypto clipboard hijacker
Campaign Scope UpdateCheck Point Research says an unknown threat actor used paid or promoted posts on legitimate news websites, fake accounts, a dedicated WordPress phishing page, GitHub and SourceForge projects, a YouTube channel created in July 2020, and coordinated VirusTotal activity to build trust around a Rust-based crypto clipboard hijacker hidden in Solana and Pump.fun sniper bots and crash-game predictors. The malware targets cryptocurrency asset holders and online gamblers, monitors Windows and macOS clipboards for wallet addresses, and swaps matching content with attacker-controlled addresses.
Show sources
- Crypto Clipper Campaign Abuses Fake Reviews, AI Narrators, and VirusTotal Comments — thehackernews.com — 17.06.2026 21:14
- Crypto Clipper Campaign Abuses Fake Reviews, AI Narrators, and VirusTotal Comments — thehackernews.com — 17.06.2026 21:14
- Fake GitHub Stars and AI Videos Mask a Crypto Clipper — www.infosecurity-magazine.com — 18.06.2026 18:00