Connect with us

Hi, what are you looking for?

Crypto
Crypto
#image_title

Cryptocurrency

Malware targeting crypto users hides in fake office add-ins

Cybercriminals have infused malware into the fake Microsoft Office add-ins that target cryptocurrency users.  The malware hides in the clipboard and changes the wallet addresses of regular users. These fake add-ins, like SourceForge, can easily rob you of your money and data without your notice.

Cybercriminals have found a smart way to take your crypto using fake Microsoft Office add-ons that steal your money.  Many users download the tools that are disguised as normal tools, as these fake add-ins are available on SourceForge. But these packages come with a stealthy malware called ClipBanker that siphons off your crypto without you knowing.

ClipBanker does its job in the background, taking over one of the most widely performed actions by crypto users: copying and pasting wallet addresses. After a user copies a wallet address to the clipboard, the malware switches it to that of the attacker’s. Most users use copy-paste instead of typing long wallet addresses, so this substitution goes unnoticed most of the time until they unknowingly send their funds to the wrong address.

One such vendor, “Office Package,” uses a fake Office add-in with download buttons copied from authentic pages. Once people install the extension, it initiates a relentless attack. The malicious program hijacks your clipboard and collects your system information like IP address, geolocation, and username, which it sends to hackers via Telegram. Moreover, it uses anti-detection techniques; if it detects any antivirus, it will erase itself to avoid detection.

Cybersecurity professionals have highlighted more alarming signs, like suspiciously small file sizes that don’t match what Office software usually produces and files that have been stuffed with random crap.

The dangers extend beyond stolen funds. When hackers seize control of the device, they can use it for other criminal activities. Other criminals could profit from this access and carry out even more devastating actions. The hackers want your crypto transaction, but they can exploit you more over time.

The interface of the fake add-in is Russian; this shows at least the Russian-speaking users are targeted.  The data shows that thousands, mostly Russians, have come across this malware already.

To protect yourself from this danger, do not download anything from unverified or unofficial sources. Furthermore, be careful about suspicious extensions, even the harmless ones. Cyber criminals are becoming even more sophisticated and are on the rise as crypto usage increases. Keeping up-to-date and following best practices is essential for safeguarding digital assets from ever-more-sophisticated attacks.

author avatar
CryptoCorn
CryptoCorn is Editor and Author at 4C Media Co. and covers all stories and news related to Crypto & Finance. Excellent blogger and Passionate Crypto Trader. Follow her on twitter at @cryptocorn7.
Advertisement

You May Also Like

Exclusive

A look into the meme coin that is ruling social media and Solana. In crypto, memes don’t just stay memes anymore. There is money...

Exclusive

FARTCOIN is one of the most popular memecoins of 2025. FARTCOIN is a cryptocurrency that stands for Fungible Arthur Robotic Token coin. FARTCOIN is...

Cryptocurrency

Cryptocurrency exchange Bitget faced an unexpected disruption on April 20 as trading on the futures contract VOXEL/USDT exploded. According to their statement, within 30...

Finance

Big names in crypto like Circle and BitGo plan to file applications for banking charters in the United States, similar to the WSJ. The...

polkadot
Polkadot (DOT) $ 4.29 0.44%
bitcoin
Bitcoin (BTC) $ 94,328.00 1.27%
ethereum
Ethereum (ETH) $ 1,804.41 0.15%
cardano
Cardano (ADA) $ 0.708517 2.33%
xrp
XRP (XRP) $ 2.20 0.30%
stellar
Stellar (XLM) $ 0.289646 0.73%
litecoin
Litecoin (LTC) $ 87.18 0.37%