Check Point Research has identified a sophisticated malware campaign using fake press releases and social media manipulation to distribute a Rust-based clipboard hijacker targeting cryptocurrency users on Windows and macOS.
Key Points
- Attackers use phishing sites, GitHub, and SourceForge to distribute malware disguised as legitimate software.
- The clipboard hijacker monitors for cryptocurrency wallet addresses and replaces them with attacker-controlled strings during transactions.
- Fake YouTube channels featuring AI-generated narrators and coordinated comments are used to build false credibility.
- Threat actors exploit newswire services to publish press releases, lending an appearance of legitimacy to their malicious projects.
- "Ghost Networks" of fake accounts manipulate reputation-based security platforms like VirusTotal to prevent the malware from being flagged.