s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-apk.clipper

📛 Threat Title

Malware family: Clipper

Category: Clipper First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `apk.clipper`. Printable name: Clipper.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain apk.clipper VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.clipper

IOC database

Type
domain
Value
apk.clipper
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-apk.clipper

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.clipper

References (1)

Remediations (10)

  • web:any.run

    What is Laplas Clipper malware ? Laplas Clipper is a family of malware that possesses stealer capabilities. Specifically, it works by replacing victims' cryptocurrency addresses with those of the attacker using the clipboard. As a result, users unknowingly end up sending their virtual coins and tokens to the wallet set up by the threat actor.

  • web:cybersecuritynews.com

    CountLoader malware uses PowerShell and JavaScript to hijack crypto transactions on thousands of infected PCs.

  • web:hunt.io

    Laplas Clipper is a clipboard hijacker malware that specifically targets cryptocurrency users. It monitors the victim's clipboard for cryptocurrency wallet addresses and replaces them with an attacker-controlled address. This results in fraudulent transactions, redirecting funds to the malicious wallet without the user's knowledge.

  • web:thehackernews.com

    Binance warns of a global clipper malware targeting cryptocurrency users, replacing wallet addresses to steal funds.

  • web:theprotectionguru.com

    Clipper malware replaces copied text with attacker-controlled info. Learn how to protect your accounts and prevent costly mistakes online.

  • web:www.binance.com

    This is a follow up blog post about the growing threat of clipper malware that Binance security team has been tackling the past months and how it is now targeting users via fake communication apps.

  • web:www.cisa.gov

    It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.

  • web:www.dlnews.com

    Binance blacklists attacker addresses linked to Clipper malware . Users advised to double-check wallet addresses before sending. Stealer-type malware increases, targets crypto transactions and wallet data.

  • web:www.malwarebytes.com

    Click Quarantine to remove the found threats. Reboot the system if prompted to complete the removal process. Business remediation How to remove Trojan.LaplasClipper with the Malwarebytes Nebula console You can use the Malwarebytes Anti- Malware Nebula console to scan endpoints. Nebula endpoint tasks menu Choose the Scan + Quarantine option.

  • web:www.threatdown.com

    Business remediation How to remove Trojan.LaplasClipper with the Malwarebytes Nebula console You can use the Malwarebytes Anti- Malware Nebula console to scan endpoints. Nebula endpoint tasks menu Choose the Scan + Quarantine option. Afterwards you can check the Detections page to see which threats were found.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.