216.73.217.80

HUMINT Operations Uncover Cryptojacking Campaign: Discord-Based Distribution of Clipboard Hijacking Malware Targeting Cryptocurrency Communities

· Published 15/01/2026 17:16 · Modified 16/01/2026 13:42

Export JSON

Essential information

Published
15/01/2026 17:16
Modified
16/01/2026 13:42
Tags
2026-01-15 clipboard hijacking cryptocurrency theft gaming communities python malware social engineering streaming
Related entities
2 observables, 1 intrusion sets (apt), 3 techniques (mitre)

Description

A sophisticated operation, orchestrated by the threat actor 'RedLineCyber', has been uncovered. The actor distributes a malicious executable named 'Pro.exe', a Python-based trojan designed for silent . This malware continuously monitors the Windows clipboard for cryptocurrency wallet addresses and substitutes them with attacker-controlled addresses. The threat actor exploits trust within Discord communities focused on gaming, gambling, and cryptocurrency . The malware demonstrates moderate technical complexity, using obfuscated Python bytecode and base64-encoded regular expressions for wallet detection. It targets cryptocurrency streamers, casino , and users who frequently handle digital asset transactions during live broadcasts. The operation has successfully compromised multiple victims across six major cryptocurrencies.

External references