Find notable cyber news and cases, enriched with sources, timelines, and signals.

Rust-based clipboard hijacker that swaps wallet addresses

Malware Activity
First reported
Last updated
Happening score
H score 10
1 unique sources, 1 articles

Summary

Hide ▲

The Rust-based clipper is a Windows and macOS malware activity that replaces copied cryptocurrency wallet addresses with attacker-controlled destinations. It continuously watches the clipboard for wallet-pattern matches and swaps in addresses from a hard-coded list, diverting transfers. The payload is concealed inside Solana and Pump.fun sniper bots and crash-game predictors, increasing theft risk for cryptocurrency users.

Related Happenings

OkoBot hardware-wallet phrase theft campaign

Campaign
H score37 First: 15.07.2026 18:30 Last: 15.07.2026 18:30 Sources 1

About this happening: An active OkoBot campaign is driving hundreds of victimizations across more than 25 countries, showing broad coordinated malware activity. The operation uses overlapping d...

Ghost Networks crypto-clipper promotion campaign

Campaign
H score15 First: 17.06.2026 21:14 Last: 17.06.2026 21:14 Sources 1

How related: The end goal of the campaign is to push a cryptocurrency clipboard hijacker that's concealed within Solana and Pump.fun sniper bots and crash-game predictors, suggesting that cryptocurrency asset holders and online gamblers on the hunt for shortcuts and quick profits are the targets.

About this happening: Unknown threat actor is running an active June 2026 campaign that fakes legitimacy to distribute a Rust-based clipboard hijacker. The operation uses bogus GitHub sta...

NFCShare fake banking-app update phishing campaign

Campaign
H score40 First: 09.06.2026 01:11 Last: 09.06.2026 01:11 Sources 1

About this happening: The NFCShare phishing campaign is using fake banking-app updates on GitHub to steal payment card data from customers of multiple banks across Europe, expanding...

JINX-0164 cryptocurrency recruitment-lure campaign

Campaign
H score39 First: 28.05.2026 10:54 Last: 28.05.2026 10:54 Sources 1

About this happening: A JINX-0164 campaign is targeting cryptocurrency firms and developers with LinkedIn recruiter lures, a fake meeting-and-fix workflow, and macOS malware to steal cr...

SHub Reaper macOS infostealer variant

Malware Activity
H score23 First: 19.05.2026 00:42 Last: 19.05.2026 00:42 Sources 1

About this happening: The SHub Reaper macOS infostealer now uses AppleScript and a fake Apple security update lure to infect Macs, raising the risk of credential theft and remote access. It...

Timeline

  1. 17.06.2026 21:14 2 articles · 28d ago

    Check Point Research identifies a Rust-based clipboard hijacker that swaps cryptocurrency wallet addresses

    Initial Disclosure

    Check Point Research identifies an unknown threat actor using paid or promoted posts, fake accounts, and Ghost Networks to promote a Rust-based clipboard hijacker hidden in Solana and Pump.fun sniper bots and crash-game predictors. The malware targets Windows and macOS systems, continuously monitors the clipboard for cryptocurrency wallet address patterns, and replaces matched addresses with attacker-controlled ones from a hard-coded list, diverting digital assets from cryptocurrency users and online gamblers.

    Show sources