Is Your Crypto Safe? XPhase Clipper Malware Steals Coins with a Click

The XPhase Clipper Malware poses a serious threat to cryptocurrency users by pilfering sensitive information.

A new strain of malware dubbed XPhase Clipper has been stealthily targeting cryptocurrency users. This Clipper malware infiltrates unsuspecting victims’ systems through deceptive websites masquerading as authentic cryptocurrency platforms. 

Source: Cyble

Cybersecurity experts at Cyble Research and Intelligence Labs (CRIL) have found this concerning trend where a large-scale operation is using cloned YouTube videos to target unsuspecting victims on the internet.

This is a churned-down version of the report, shedding light on its modus operandi and the infection chain of XPhase Clipper malware. 

Understanding the XPhase Clipper Malware Campaign

Source: Cyble

Clipper malware poses a serious threat to cryptocurrency users by pilfering sensitive information, particularly cryptocurrency wallet addresses, from the clipboard. 

With the increasing popularity of cryptocurrencies like Bitcoin and Ethereum, cybercriminals are increasingly exploiting users to abscond with their funds.

XPhase Clipper represents a sophisticated iteration of this malware strain, designed to intercept and manipulate copied cryptocurrency wallet addresses, rerouting funds to the attackers’ accounts. 

The threat actors behind the XPhase Clipper malware campaign are exclusively targeting cryptocurrency users worldwide, deploying a series of deceptive tactics to ensnare victims. 

Source: Cyble

Notably, phishing sites impersonating reputable platforms such as Metamask and Wazirx have emerged as conduits for spreading the XPhase Clipper payload.

Source: Cyble

These malicious sites lure users into downloading a zip file housing an array of malicious components, including a dropper executable, VB Script, and Batch script files, culminating in the execution of the clipper payload in the form of a DLL file.

Source: Cyble

XPhase Clipper Malware Targets Indian Crypto Users

Upon closer examination, CRIL found that the infection chain is meticulously orchestrated, with each stage serving to conceal the malicious activities of the XPhase Clipper. 

The VB Script plays an important role in facilitating the download and execution of the clipper payload, while the Batch script ensures persistence by adding a registry entry for automatic execution of the malware upon system startup. 

Source: Cyble

Such obfuscation tactics, coupled with the deployment of deceptive error messages, serve to hide the malware’s operations and evade detection.

A closer look at the campaign reveals a discernible pattern in the targeting strategy employed by the threat actors.

While the campaign casts a wide net, with cryptocurrency users worldwide falling prey to its machinations, there is a noticeable emphasis on targeting specific demographics, notably Indian cryptocurrency enthusiasts.

Media Disclaimer: This report is based on internal and external research obtained through various means. The information provided is for reference purposes only, and users bear full responsibility for their reliance on it. The Cyber Express assumes no liability for the accuracy or consequences of using this information.

Ashish Khaitan

Ashish is a technical writer at The Cyber Express. He adores writing about the latest technologies and covering the latest cybersecurity events. In his free time, he likes to play horror and open-world video games.

Recent Posts

Gunra Ransomware Builds a New Attack Network Through RaaS

The joint advisory was published August 10, 2026, as part of the ongoing #StopRansomware initiative.

8 hours ago

New Zealand Targets Russian Cyber Actors With Fresh Sanctions

New Zealand has now imposed sanctions on more than 2,000 Russian individuals, entities and vessels, alongside trade restrictions. T

12 hours ago

Suisun City Declares Emergency After Cyberattack Disrupts Systems

Suisun City Emergency follows a cyberattack that shut down the city’s IT network, disrupting police, fire and 911 communications.

1 day ago

AI Agent Exploits Gym System Vulnerability, Cancels Waitlist Booking in Australia

An AI agent exploited a gym system vulnerability in Australia, booked classes months ahead and cancelled another user's reservation.

1 day ago

Ransomware Kingpin Gets 16 Years for Global Cyberattacks

The Justice Department’s Office of International Affairs provided substantial assistance with Silnikau’s extradition and the collection of evidence.

1 day ago

Levi Strauss Hit by Cyberattack, Corporate Files Accessed

The Levi Strauss cyberattack comes as several major retailers have reported cybersecurity incidents involving their own systems or third-party service…

2 days ago

This website uses cookies. By continuing to use this website you are giving consent to cookies being used.

Read More