Stay safe from the BTC clipper. Dangerous malware

Lipstick Spoiler

Supreme Member
Jr. VIP
Joined
Aug 10, 2022
Messages
1,410
Reaction score
914
Hey guys, so just today only, i was setting up my shop and filling crypto details.
I copied my BTC and ETH address in my mobile, and i sent it to telegram web.
From there, i copied it, and when i was pasting it in my shop, the BTC address was different from my own wallet address. Luckily, i noticed this. I thought this would be some sort of a glitch, so i again copied, but boom, again the same btc address which was different from mine. I copied eth and ltc address too, but again, the pasted address was different from the copied one. I was scratching my head, and Googled it.

I found it was some sort of a malware that was doing it, and it was present in my computer. Damn!! I was seriously blown away.

Please guys, you also check it if there's anything present of that sort or not. I had a file by the name davire.exe, and I deleted it, and now the copy and paste, both are same.

I am still a bit paranoid, so i have decided to format my laptop, and i purchased mega.nz for transferring my data.


I found a tool which detects it for you. If mods allow me, i can post that here.

But please be safe, and do the experiment of copy pasting to see if there's any stealer present.
 
yea this malware has been around for a while, luckily it is not very stealth so easy to remove.
however there might be more on your system, so yes formating and re-install is always a good idea after compromise.
just make sure that the malware is not in your backed up data as well ;)
 
however there might be more on your system, so yes formating and re-install is always a good idea after compromise.
just make sure that the malware is not in your backed up data as well ;)
yes i read it that it goes into the hardware lol

I have purchased the Malwarebytes now. Let's scan the computer and transfer the data.
 
So this malware look for crypto addresses in Windows clipboard(copy and paste data) and alters the address to the attackers address to trick the user to send crypto the attackers address instead .That is so simple to code,The scams that people think of is getting out of hand the recession will make it worse.
 
Ahhh. Crypto Clippers. I thought they were extinct. Could you send me those adresses or would you check them how much they recieved -> (BTC Explorer)
 
What I do to avoid constant copying pasting my address on my pc is
Put my address(s) (eth/btc/poly etc) and their QR code in an encrypted notepad like standard notes
and when need it, i just open it up on my phone and grab it.
Another way is if you have a Web3 profile like UD.me can just grab it from there.
or i just use my wallet on my phone to copy there instead :)
 
yes i read it that it goes into the hardware lol

I have purchased the Malwarebytes now. Let's scan the computer and transfer the data.
nah this one doesn't use a hardware rootkit. that would make it persistent even after you format and you wouldn't see the .exe and easily delete it, it would be hidden from AVs and anti malware scanners.
and if you use a recovery cd to delete it, it would be re-created as no AV or malware scanner can get rid of hardware backdoors sofar. that would have to be done manually and won't be easy.
don't worry though these backdoors are never used by scammers as they arent advanced enough to code that type of malware.
these rootkits are only used by real hackers and nation states to hide their malware ;)

What I do to avoid constant copying pasting my address on my pc is
Put my address(s) (eth/btc/poly etc) and their QR code in an encrypted notepad like standard notes
and when need it, i just open it up on my phone and grab it.
Another way is if you have a Web3 profile like UD.me can just grab it from there.
or i just use my wallet on my phone to copy there instead :)
that can also be intercepted, besides there is the same type of malware for phones as well.
 
nah this one doesn't use a hardware rootkit. that would make it persistent even after you format and you wouldn't see the .exe and easily delete it, it would be hidden from AVs and anti malware scanners.
and if you use a recovery cd to delete it, it would be re-created as no AV or malware scanner can get rid of hardware backdoors sofar. that would have to be done manually and won't be easy.
don't worry though these backdoors are never used by scammers as they arent advanced enough to code that type of malware.
these rootkits are only used by real hackers and nation states to hide their malware ;)


that can also be intercepted, besides there is the same type of malware for phones as well.
But you know there hardware backdoors like intel management engine and amd psp built in that the US goverment have control of.
 
But you know there hardware backdoors like intel management engine and amd psp built in that the US goverment have control of.
i know about that as well as SMM based kits, thats why i said "nation states" have access to this type of backdoors.
 
Ahhh. Crypto Clippers. I thought they were extinct. Could you send me those adresses or would you check them how much they recieved -> (BTC Explorer)
Umm sorry dude, i forgot to copy them. They would have raked in some bucks of course. I'm poor, so they couldn't get anything from me lol
 
You want to say that your system got infected and that is why this was happening ?
 
So this malware look for crypto addresses in Windows clipboard(copy and paste data) and alters the address to the attackers address to trick the user to send crypto the attackers address instead .That is so simple to code,The scams that people think of is getting out of hand the recession will make it worse.

It's quite worrying that a lot of people will not notice this too, just run a copy and paste and send.
 
Watch out when transferring data, as advanced malware can bind to existing files. In your case, it seems like the virus was detected and removed, but another full scan using different software won't hurt.
 
You want to say that your system got infected and that is why this was happening ?
Yes, try to copy btc address, and when you paste, make sure it is the same. If it isn't, you have the btc clipper malware. I think i downloaded some not so known extensions, and then his happened.
 
What did you download or do recently to get this malware into your computer?
I don't know bro. I was copying and pasting my btc address, and luckily i noticed that it got changed, so i did it again for eth and ltc. Then also, it got changed, then i Googled it. Luckily i found the solution. Maybe I had downloaded some cracked software or exe or any chrome extension.
 
I don't know bro. I was copying and pasting my btc address, and luckily i noticed that it got changed, so i did it again for eth and ltc. Then also, it got changed, then i Googled it. Luckily i found the solution. Maybe I had downloaded some cracked software or exe or any chrome extension.
Cracked software most likely. Did you have an antivirus installed before you got infected?
Also I can vouch for Malwarebytes, I've been using it for 1 year.
 
Cracked software most likely. Did you have an antivirus installed before you got infected?
Also I can vouch for Malwarebytes, I've been using it for 1 year
i mostly use rdp, so i don't have any issues as such. But yeah, i use av in my original computer for sure.
 
Back
Top