Cyble Research & Intelligence Labs has identified ClipXDaemon, a new Linux malware targeting cryptocurrency users on X11 desktop environments. Delivered via a bincrypter-based three-stage loader (encrypted loader → in-memory dropper → on-disk ELF), the payload is a fully autonomous clipboard hijacker with no C2 infrastructure.

13m read timeFrom cyble.com
Post cover image
Table of contents
Executive SummaryKey TakeawaysBackground & Threat LandscapeTechnical AnalysisConclusionMITRE ATT&CK® TechniquesIndicators of Compromise (IOCs)

Sort: