Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Discord Exploited to Spread Clipboard Hijacker Stealing Cryptocurrency Funds

## Cybersecurity: Cryptocurrency Theft Operation by RedLineCyber

Cybersecurity: Cryptocurrency Theft Operation by RedLineCyber

The CloudSEK STRIKE team has identified a sophisticated cryptocurrency theft operation conducted by the threat actor "RedLineCyber." This actor impersonates RedLine Solutions to gain credibility in underground communities.

The malware employed does not collect comprehensive system data but instead uses a targeted approach. It monitors the Windows clipboard for cryptocurrency wallet addresses and substitutes them with attacker-controlled addresses when users attempt to paste them. This technique increases the attack's effectiveness while minimizing detection.

The threat actor targets trust relationships within Discord communities related to gaming, gambling, and cryptocurrency streaming. A targeted campaign was identified in December 2025, leveraging Discord to distribute Pro.exe, a Python-based clipboard-hijacking trojan designed to substitute cryptocurrency addresses during transactions.

Distribution involves social engineering, where RedLineCyber builds relationships with potential victims, including cryptocurrency streamers and influencers, before introducing the malware as a "clipboard protection tool" or "streaming utility." Eight primary Discord communities, including those for crypto streaming and gaming, were actively targeted.

Pro.exe is a moderately sophisticated malware packaged as a PyInstaller executable containing obfuscated Python 3.13 bytecode. It uses base64-encoded regular expressions for wallet detection and basic persistence through Windows Registry Run keys.

Upon execution, it creates a %APPDATA%\CryptoClipboardGuard\ directory and establishes an autostart entry. The monitoring mechanism operates on a 300-millisecond cycle, allowing near-real-time detection while maintaining low CPU utilization.

When new clipboard content is detected, base64-encoded regex patterns identify wallet addresses across six cryptocurrency formats:

The malware employed does not collect comprehensive system data but instead uses a targeted approach.
Benjamin Scott · Thehackingpost

Bitcoin (BTC): SegWit format Ethereum (ETH): Hex-encoded address format Solana (SOL): Base58 encoding validation Dogecoin (DOGE): Prefixed base58 format Litecoin (LTC): Bech32 format Tron (TRX): T-prefix base58 format

Detected wallet addresses are replaced with attacker-controlled addresses, and logs are maintained in activity.log for tracking infections and theft effectiveness.

The malware's focus on clipboard monitoring without network communication results in a low detection profile. VirusTotal analysis shows 34 of 69 antivirus vendors flagging the sample under various classifications. The lack of command-and-control infrastructure eliminates network-based detection vectors.

Blockchain analysis shows successful financial theft from multiple victims. RedLineCyber uses separate wallets for each cryptocurrency. They also advertised stolen LinkedIn credentials on the BreachStars marketplace in October 2025, indicating a diversified criminal operation.

Indicator Type Value Context

Advertisement

SHA-256 0d6e83e240e41013a5ab6dfd847c689447755e8b162215866d7390c793694dc6 Primary sample (Pro.exe / peeek.exe)

SHA-256 d011068781cfba0955258505dbe7e5c7d3d0b955e7f7640d2f1019d425278087 Related ClipBanker variant

File Path %APPDATA%\CryptoClipboardGuard\activity.log Clipboard swap activity log

Directory %APPDATA%\CryptoClipboardGuard\ Persistence directory

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories