BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

New MassJacker Malware Targets Users Pirating Software, Steals Over $336,000 in Cryptocurrency

  • New Malware campaign called MassJacker targets users searching for pirated software, monitoring clipboard content to steal cryptocurrency by replacing wallet addresses.
  • Researchers have identified over 778,531 attacker-controlled wallet addresses, with transactions totaling approximately $336,700 diverted through this clipper malware.
  • The malware shares code similarities with MassLogger and employs sophisticated evasion techniques including JIT hooking and custom virtual machines to avoid detection.

Cryptocurrency users face a growing threat from a newly discovered malware strain designed to hijack digital asset transfers through clipboard manipulation. Security researchers at CyberArk have identified "MassJacker," a sophisticated clipper malware targeting individuals who search for pirated software, with stolen funds already approaching $340,000.

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading

The malware operates by monitoring victims’ clipboard content and automatically replacing cryptocurrency wallet addresses with attacker-controlled alternatives, effectively redirecting transactions to malicious wallets instead of intended recipients.

According to CyberArk researcher Ari Novick, "The infection chain begins at a site called pesktop[.]com. This site, which presents itself as a site to get pirated software, also tries to get people to download all sorts of malware."

The attack sequence initiates when users download what appears to be pirated software. The executable then triggers a PowerShell script that delivers multiple payloads, including the established Amadey botnet and two specialized .NET binaries (32-bit and 64-bit versions). These components work together to install the MassJacker clipper, using a legitimate Windows process ("InstalUtil.exe") as cover for its malicious activities.

MassJacker represents a type of Microsoft-warns-of-cryware-info.html”>cryware (a term coined by Microsoft) specifically designed to intercept cryptocurrency transactions. This particular strain employs several advanced evasion techniques, including:

- Advertisement -
  • Just-In-Time (JIT) hooking to evade detection
  • Metadata token mapping that conceals function calls
  • A custom virtual machine interpreting commands rather than executing standard .NET code
  • Built-in anti-debugging protections

"MassJacker creates an event handler to run whenever the victim copies anything," explained Novick. "The handler checks the regexes, and if it finds a match, it replaces the copied content with a wallet belonging to the threat actor from the downloaded list."

The financial impact appears substantial. CyberArk’s investigation revealed over 778,531 unique cryptocurrency addresses controlled by the attackers. While only 423 addresses contained active funds totaling approximately $95,300, the researchers determined that the total value of digital assets processed through these wallets reached approximately $336,700 before being transferred out.

Most concerning, a single wallet in the network currently holds approximately $87,000 (600 SOL), with over 350 separate transactions funneling money into this address from various sources.

Although the operators behind MassJacker remain unidentified, analysis of the malware’s code structure revealed significant similarities with MassLogger, another malicious tool that employs similar JIT hooking techniques to resist analysis. This connection potentially indicates shared development resources or methodologies.

The discovery of MassJacker joins increasing warnings about Binance-warns-of-rising-clipper-malware.html”>clipper malware targeting cryptocurrency users, highlighting the continued evolution of threats aimed at digital asset holders.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Criminals’ Bitcoin Seized: $34M Recovered by Irish Bureau

Ireland's Criminal Assets Bureau (CAB) has accessed a cryptocurrency wallet containing 500 Bitcoin, valued...

Pump.fun Restricts Creator Fee Changes To One

Pump.fun has limited memecoin creators to just one post-launch change to fee recipient wallets.The...

Cardano Rebounds, But $0.50 in Sight for 2026?

Cardano (ADA) has gained 3% in the last 24 hours but remains down 7.7%...

$35M in Bitcoin seized after police crack lost wallet

Irish police, with Europol's help, have seized 500 Bitcoin (worth over $35 million) from...

Gold Crashes to 4-Month Low; Strategists Keep $5K–$6.3K Targets

Gold crashed to a four-month low of $4,098, posting its worst five-session performance since...

Must Read

Top Best Metaverse Worlds To Buy Land

The metaverse has grown in our everyday conversation since Facebook announced its rebranding in October 2021 to META. The metaverse is a virtual world,...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading