New MassJacker Malware Targets Users Pirating Software, Steals Over $336,000 in Cryptocurrency

  • New Malware campaign called MassJacker targets users searching for pirated software, monitoring clipboard content to steal cryptocurrency by replacing wallet addresses.
  • Researchers have identified over 778,531 attacker-controlled wallet addresses, with transactions totaling approximately $336,700 diverted through this clipper malware.
  • The malware shares code similarities with MassLogger and employs sophisticated evasion techniques including JIT hooking and custom virtual machines to avoid detection.

Cryptocurrency users face a growing threat from a newly discovered malware strain designed to hijack digital asset transfers through clipboard manipulation. Security researchers at CyberArk have identified "MassJacker," a sophisticated clipper malware targeting individuals who search for pirated software, with stolen funds already approaching $340,000.

- Advertisement -

The malware operates by monitoring victims’ clipboard content and automatically replacing cryptocurrency wallet addresses with attacker-controlled alternatives, effectively redirecting transactions to malicious wallets instead of intended recipients.

According to CyberArk researcher Ari Novick, "The infection chain begins at a site called pesktop[.]com. This site, which presents itself as a site to get pirated software, also tries to get people to download all sorts of malware."

The attack sequence initiates when users download what appears to be pirated software. The executable then triggers a PowerShell script that delivers multiple payloads, including the established Amadey botnet and two specialized .NET binaries (32-bit and 64-bit versions). These components work together to install the MassJacker clipper, using a legitimate Windows process ("InstalUtil.exe") as cover for its malicious activities.

MassJacker represents a type of Microsoft-warns-of-cryware-info.html”>cryware (a term coined by Microsoft) specifically designed to intercept cryptocurrency transactions. This particular strain employs several advanced evasion techniques, including:

- Advertisement -
  • Just-In-Time (JIT) hooking to evade detection
  • Metadata token mapping that conceals function calls
  • A custom virtual machine interpreting commands rather than executing standard .NET code
  • Built-in anti-debugging protections

"MassJacker creates an event handler to run whenever the victim copies anything," explained Novick. "The handler checks the regexes, and if it finds a match, it replaces the copied content with a wallet belonging to the threat actor from the downloaded list."

The financial impact appears substantial. CyberArk’s investigation revealed over 778,531 unique cryptocurrency addresses controlled by the attackers. While only 423 addresses contained active funds totaling approximately $95,300, the researchers determined that the total value of digital assets processed through these wallets reached approximately $336,700 before being transferred out.

Most concerning, a single wallet in the network currently holds approximately $87,000 (600 SOL), with over 350 separate transactions funneling money into this address from various sources.

Although the operators behind MassJacker remain unidentified, analysis of the malware’s code structure revealed significant similarities with MassLogger, another malicious tool that employs similar JIT hooking techniques to resist analysis. This connection potentially indicates shared development resources or methodologies.

The discovery of MassJacker joins increasing warnings about Binance-warns-of-rising-clipper-malware.html”>clipper malware targeting cryptocurrency users, highlighting the continued evolution of threats aimed at digital asset holders.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -

Latest News

Corvex Lands Nvidia H200 GPU Lease for Battery AI R&D to IPO

Corvex signed a long-term lease to deploy NVIDIA H200 GPUs for an AI-driven battery...

Kansas bill would create Bitcoin reserve from unclaimed prop

Kansas lawmakers introduced a state-managed Bitcoin and digital assets reserve funded through unclaimed property.The...

Capital One to Buy Brex for $5.15B; Cards Interest Boost now

Capital One will buy Brex for $5.15 billion in a deal set to close...

Sen. Lummis says CLARITY Act unites crypto, urges quick vote

Senator Cynthia Lummis says renewed alignment across the crypto industry has boosted momentum for...

Negative XRP Funding Mirrors Past Setups Ahead of Rally Soon

XRP perpetual funding rates on Binance have been negative recently, signaling a bearish derivatives...
- Advertisement -

Must Read

Forex Trading Vs Crypto Trading: Which One Should You Choose?

So you're trying to decide between two types of trading: Forex and cryptocurrency.Forex trading is the big player in the trading world, with lots...
🔥 #AD Get 20% OFF any new 12 month hosting plan from Hostinger. Click here!