Cyble Research & Intelligence Labs has identified ClipXDaemon, a new Linux malware targeting cryptocurrency users on X11 desktop environments. Delivered via a bincrypter-based three-stage loader (encrypted loader → in-memory dropper → on-disk ELF), the payload is a fully autonomous clipboard hijacker with no C2 infrastructure.
Table of contents
Executive SummaryKey TakeawaysBackground & Threat LandscapeTechnical AnalysisConclusionMITRE ATT&CK® TechniquesIndicators of Compromise (IOCs)Sort: